CVE-2006-4210 Information
Feb 14, 2021
cve
Description
nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1 when register_globals is enabled allows remote attackers to use the server as an open mail relay via modified mail_text2 user_row[5] nu_mail_1 and shop_mail parameters. NOTE: some of these details are obtained from third party information.
Reference
http://secunia.com/advisories/21454 http://www.securityfocus.com/bid/19517 https://exchange.xforce.ibmcloud.com/vulnerabilities/28366 https://www.exploit-db.com/exploits/2181
Share on: