5
CVSSv2

CVE-2006-7087

Published: 02/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in the mail function in Dotdeb PHP prior to 5.2.0 Rev 3 allows remote malicious users to bypass the protection scheme and inject arbitrary email headers via CRLF sequences in the query string, which is processed via the PHP_SELF variable.

Vulnerable Product Search on Vulmon Subscribe to Product

dotdeb dotdeb php 4.4

dotdeb dotdeb php 5.0

dotdeb dotdeb php 5.1

dotdeb dotdeb php 5.2

dotdeb dotdeb php 4.4.3

dotdeb dotdeb php 4.4.4