VYPR
Unrated severityNVD Advisory· Published Jun 30, 2001· Updated Apr 16, 2026

CVE-2001-1246

CVE-2001-1246

Description

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

Affected products

1
  • cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
    Range: >=4.0.5,<=4.1.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.