CVE-2009-4111: Code Injection
Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remote attackers to read and write arbitrary files via a crafted $recipients parameter, and possibly other parameters, a different vulnerability than CVE-2009-4023.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4111?
CVE-2009-4111 has a medium severity rating due to its potential for remote file manipulation.
How do I fix CVE-2009-4111?
To fix CVE-2009-4111, update to a version of PEAR Mail that is not affected, such as any version after 1.2.0b2.
What versions of PEAR Mail are affected by CVE-2009-4111?
CVE-2009-4111 affects PEAR Mail version 1.1.14, 1.2.0b2, and possibly other versions.
Could CVE-2009-4111 allow remote attackers to compromise my system?
Yes, CVE-2009-4111 could allow remote attackers to read and write arbitrary files on the server.
What are the implications of CVE-2009-4111 for web applications using PEAR Mail?
The implications of CVE-2009-4111 may include unauthorized access to sensitive files and potential data leakage.