7.8
CVSSv2

CVE-2007-1718

Published: 28/03/2007 Updated: 30/10/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:N/I:C/A:N

Vulnerability Summary

CRLF injection vulnerability in the mail function in PHP 4.0.0 up to and including 4.4.6 and 5.0.0 up to and including 5.2.1 allows remote malicious users to inject arbitrary e-mail headers and possibly conduct spam attacks via a control character immediately following folding of the (1) Subject or (2) To parameter, as demonstrated by a parameter containing a "\r\n\t\n" sequence, related to an increment bug in the SKIP_LONG_HEADER_SEP macro.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.0.1

php php 4.0.2

php php 4.0.7

php php 4.0

php php 4.2.3

php php 4.2

php php 4.3.4

php php 4.3.5

php php 4.4.3

php php 4.4.4

php php 5.0.0

php php 5.0.5

php php 5.0

php php 5.1.4

php php 5.1.5

php php 4.0.3

php php 4.1.0

php php 4.1.1

php php 4.3.0

php php 4.3.1

php php 4.3.6

php php 4.3.7

php php 4.4.5

php php 4.4.6

php php 5.1.0

php php 5.1.6

php php 5.2.0

php php 4.0.5

php php 4.0.6

php php 4.2.1

php php 4.2.2

php php 4.3.2

php php 4.3.3

php php 4.4.1

php php 4.4.2

php php 5.0.3

php php 5.0.4

php php 5.1.2

php php 5.1.3

php php 4.0.0

php php 4.0.4

php php 4.1.2

php php 4.2.0

php php 4.3.10

php php 4.3.11

php php 4.3.8

php php 4.3.9

php php 4.4.0

php php 5.0.1

php php 5.0.2

php php 5.1.1

php php 5.2.1

Vendor Advisories

Stefan Esser discovered multiple vulnerabilities in the “Month of PHP bugs” ...
Several remote vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language, which may lead to the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-1286 Stefan Esser discovered an overflow in the object reference handling code of the un ...
Several remote vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language, which may lead to the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-1286 Stefan Esser discovered an overflow in the object reference handling code of the un ...

Exploits

source: wwwsecurityfocuscom/bid/23145/info PHP is prone to an email-header-injection vulnerability because it fails to properly sanitize user-supplied input when constructing email messages Exploiting this issue allows a malicious user to create arbitrary email headers, and then create and transmit spam messages from the affected comput ...