Description
The PHP mail function does not properly sanitize user input. Because of this, a user may pass ASCII control characters to the mail() function that could alter the headers of email. This could result in spoofed mail headers.
Affected PHP versions (up to 4.2.2).
Remediation
Upgrade PHP to the latest version.
References
Related Vulnerabilities
WordPress Plugin April's Super Functions Pack Cross-Site Scripting (1.4.7)
WordPress Plugin Request a Quote Cross-Site Scripting (2.3.4)
WordPress Plugin Easy WP SMTP Cross-Site Scripting (1.2.4)
Microsoft SQL Server Improper Input Validation Vulnerability (CVE-1999-0999)
WordPress Plugin WordPress Clean Up & Optimizer-Clean Up Optimizer SQL Injection (3.0.13)