Description
CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1295-1 | New php5 packages fix several vulnerabilities |
Debian DSA |
DSA-1296-1 | New php4 packages fix privilege escalation |
EUVD |
EUVD-2007-2502 | CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands. |
Ubuntu USN |
USN-462-1 | PHP vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T13:42:32.622Z
Reserved: 2007-05-07T00:00:00.000Z
Link: CVE-2007-2509
No data.
Status : Deferred
Published: 2007-05-09T00:19:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-2509
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN