CVE-2006-4210
phPay <2.02.1 - Open Mail Relay
Title source: llmDescription
nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. NOTE: some of these details are obtained from third party information.
Exploits (1)
References (4)
Scores
EPSS
0.0716
EPSS Percentile
91.6%
Details
Status
published
Products (2)
andreas_kansok/phpay
2.02
andreas_kansok/phpay
2.02.1
Published
Aug 17, 2006
Tracked Since
Feb 18, 2026