Unrated severityNVD Advisory· Published Sep 24, 2002· Updated Apr 16, 2026
CVE-2002-0985
CVE-2002-0985
Description
Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- www.debian.org/security/2002/dsa-168nvdBroken LinkPatchVendor Advisory
- www.redhat.com/support/errata/RHSA-2002-213.htmlnvdBroken LinkPatchVendor Advisory
- marc.infonvdThird Party Advisory
- marc.infonvdThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/9966nvdThird Party AdvisoryVDB Entry
- ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-008.0.txtnvdBroken Link
- distro.conectiva.com.br/atualizacoes/nvdBroken Link
- www.mandrakesoft.com/security/advisoriesnvdBroken Link
- www.novell.com/linux/security/advisories/2002_036_modphp4.htmlnvdBroken Link
- www.osvdb.org/2111nvdBroken Link
- www.redhat.com/support/errata/RHSA-2002-214.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2002-243.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2002-244.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2002-248.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2003-159.htmlnvdBroken Link
News mentions
0No linked articles in our index yet.