Description
Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2012-1746 Vulnerability (CVE-2012-1746)
WordPress Plugin Really Simple Gallery Multiple Vulnerabilities (1.4)
OpenVPN AS Use After Free Vulnerability (CVE-2023-46850)
WordPress Plugin Fancy Product Designer-WooCommerce Arbitrary File Upload (4.6.8)
WordPress Plugin Anti Plagiarism Cross-Site Scripting (3.60)