PT-2007-3084 · Php+1 · Php+1
Publicado
2007-03-28
·
Atualizado
2018-10-30
·
CVE-2007-1718
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions:
PHP versions 4.0.0 through 4.4.6
PHP versions 5.0.0 through 5.2.1
Description:
A CRLF injection issue in the mail function allows remote attackers to inject arbitrary e-mail headers, possibly leading to spam attacks. This is achieved by including a control character immediately following the folding of the
Subject or To parameter, such as a sequence like r t . The issue is related to an increment bug in the SKIP LONG HEADER SEP macro.Recommendations:
For PHP versions 4.0.0 through 4.4.6, update to a version outside of this range to resolve the issue.
For PHP versions 5.0.0 through 5.2.1, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider validating and sanitizing the
Subject and To parameters in the mail function to prevent CRLF injection attacks.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Php
Red Hat