PT-2016-5395 · Php+1 · Php+1

Pere Orga

·

Published

2016-04-12

·

Updated

2022-05-17

·

CVE-2016-3166

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Drupal versions 6.x before 6.38
Description A CRLF injection issue exists in the drupal set header function when used with PHP before 5.1.2, allowing remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module that allows user-submitted data to appear in HTTP headers.
Recommendations For Drupal versions 6.x before 6.38, update to version 6.38 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-3166
GHSA-FG5Q-R2Q5-QMH3

Affected Products

Drupal
Php