CRLF injection vulnerability in the mail function in Dotdeb PHP before 5.2.0 Rev 3 allows remote attackers to bypass the protection scheme and inject arbitrary email headers via CRLF sequences in the query string, which is processed via the PHP_SELF variable.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2007-03-02 21:18
Updated : 2024-02-28 11:01
NVD link : CVE-2006-7087
Mitre link : CVE-2006-7087
CVE.ORG link : CVE-2006-7087
JSON object : View
Products Affected
dotdeb
- dotdeb_php
CWE