CVE-2009-4023

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
29/11/2009
Last modified:
09/04/2025

Description

Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allows remote attackers to read and write arbitrary files via a crafted $from parameter, a different vector than CVE-2009-4111.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pear:pear:1.1.14:*:*:*:*:*:*:*