Description
The PHP mail function does not properly sanitize user input. Because of this, a user may pass ASCII control characters to the mail() function that could alter the headers of email. This could result in spoofed mail headers.
Affected PHP versions (up to 4.2.2).
Remediation
Upgrade PHP to the latest version.
References
Related Vulnerabilities
MySQL CVE-2024-20975 Vulnerability (CVE-2024-20975)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-7002)
Oracle Database Server CVE-2006-0287 Vulnerability (CVE-2006-0287)
WordPress Plugin WP Table Builder-WordPress Table Cross-Site Scripting (1.4.6)
WordPress 'wp-register.php' Multiple Cross-Site Scripting Vulnerabilities (2.0 - 2.0.1)