Vulnerability Description
CRLF injection vulnerability in the mail function in Dotdeb PHP before 5.2.0 Rev 3 allows remote attackers to bypass the protection scheme and inject arbitrary email headers via CRLF sequences in the query string, which is processed via the PHP_SELF variable.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dotdeb | Dotdeb Php | 4.4 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-November/050712.htmlVendor Advisory
- http://secunia.com/advisories/22877Vendor Advisory
- http://www.dotdeb.org/news/severe_security_hole_in_php_packagesPatchVendor Advisory
- http://www.hardened-php.net/advisory_142006.139.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/451528/100/0/threaded
- http://www.securityfocus.com/archive/1/451839/100/0/threaded
- http://www.securityfocus.com/bid/21075PatchVendor Advisory
- http://www.vupen.com/english/advisories/2006/4531
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30251
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-November/050712.htmlVendor Advisory
- http://secunia.com/advisories/22877Vendor Advisory
- http://www.dotdeb.org/news/severe_security_hole_in_php_packagesPatchVendor Advisory
- http://www.hardened-php.net/advisory_142006.139.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/451528/100/0/threaded
- http://www.securityfocus.com/archive/1/451839/100/0/threaded
FAQ
What is CVE-2006-7087?
CVE-2006-7087 is a vulnerability with a CVSS score of 5.0 (MEDIUM). CRLF injection vulnerability in the mail function in Dotdeb PHP before 5.2.0 Rev 3 allows remote attackers to bypass the protection scheme and inject arbitrary email headers via CRLF sequences in the ...
How severe is CVE-2006-7087?
CVE-2006-7087 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-7087?
Check the references section above for vendor advisories and patch information. Affected products include: Dotdeb Dotdeb Php.