peter bassill · operator
$ cve CVE-2006-1015 JSON

CVE-2006-1015 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 12.4% (pctl 96)

Patch early

A public exploit exists.

Description

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS12.4% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2006-03-07
Last modified2026-06-16

Affected (1)

VendorProduct
phpphp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD