peter bassill · operator
$ cve CVE-2001-1246 JSON

CVE-2001-1246 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 9.7% (pctl 95)

Patch early

A public exploit exists.

Description

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS9.73% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-88
On CISA KEVno
Public exploityes
Published2001-06-30
Last modified2026-06-16

Affected (1)

VendorProduct
phpphp

Public exploits

SourceTitleDate
exploit-dbPHP 4.x - SafeMode Arbitrary File Execution2001-06-30

References

→ the Explorer  ·  watch your stack  ·  NVD