Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP mb_send_mail多个安全绕过漏洞
Vulnerability Description
在某些PHP 4.x 和 5.x 应用程序中的参数注入漏洞,当发送邮件和接收远程输入使用到位于mb_send_mail 函数中的additional_parameters参数时,允许按内容攻击者通过向发送邮件提供extra -C 和 -X 参数,阅读和创建任意文件。注意:这是一类技术性漏洞,而非特殊情况,对此可能尚有争论。
CVSS Information
N/A
Vulnerability Type
N/A