CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary e-mail headers via line feeds (LF) in the "To" address argument.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Php | — | Upgrade to PHP version 5.1.0 | Oct 1, 2012 | Nov 29, 2005 |
| Suse | — | Upgrade mod_php4-servletUpgrade apache2-mod_php4Upgrade php4-mysqlUpgrade php4-sysvshmUpgrade php4-sessionUpgrade php4-fastcgiUpgrade php4-develUpgrade php4-mbstringUpgrade php4-recodeUpgrade php4-imapUpgrade php4-pearUpgrade apache-mod_php4Upgrade mod_php4-coreUpgrade php4-exif | Feb 17, 2015 | Nov 29, 2005 |
| Ubuntu | — | Upgrade php4-cgiUpgrade php4-cliUpgrade php4-gdUpgrade libapache2-mod-php4Upgrade php5-gdUpgrade php5-cli | Nov 8, 2024 | Nov 29, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub