CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.
References
Link Providers
http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2007-0889.html cve-icon cve-icon
http://secunia.com/advisories/25187 cve-icon cve-icon
http://secunia.com/advisories/25191 cve-icon cve-icon
http://secunia.com/advisories/25255 cve-icon cve-icon
http://secunia.com/advisories/25318 cve-icon cve-icon
http://secunia.com/advisories/25365 cve-icon cve-icon
http://secunia.com/advisories/25372 cve-icon cve-icon
http://secunia.com/advisories/25445 cve-icon cve-icon
http://secunia.com/advisories/25660 cve-icon cve-icon
http://secunia.com/advisories/26048 cve-icon cve-icon
http://secunia.com/advisories/26967 cve-icon cve-icon
http://secunia.com/advisories/27351 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200705-19.xml cve-icon cve-icon
http://securityreason.com/securityalert/2672 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2007-231.htm cve-icon cve-icon
http://us2.php.net/releases/4_4_7.php cve-icon cve-icon
http://us2.php.net/releases/5_2_2.php cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1295 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1296 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:102 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:103 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0349.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0355.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0888.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/463596/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/23813 cve-icon cve-icon
http://www.securityfocus.com/bid/23818 cve-icon cve-icon
http://www.securitytracker.com/id?1018022 cve-icon cve-icon
http://www.trustix.org/errata/2007/0017/ cve-icon cve-icon
http://www.ubuntu.com/usn/usn-462-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2187 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/34413 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-2509 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10839 cve-icon cve-icon
https://rhn.redhat.com/errata/RHSA-2007-0348.html cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-2509 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-05-09T00:00:00

Updated: 2024-08-07T13:42:32.622Z

Reserved: 2007-05-07T00:00:00

Link: CVE-2007-2509

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-05-09T00:19:00.000

Modified: 2024-11-21T00:30:57.753

Link: CVE-2007-2509

cve-icon Redhat

Severity : Low

Publid Date: 2007-05-03T00:00:00Z

Links: CVE-2007-2509 - Bugzilla