PHP.Function.CRLF.Injection

description-logoDescription

It indicates an attacker attempted to exploit a Email Composition CRLF Injection Vulnerability in PHP. Certain versions of PHP contain a CRLF Injection Vulnerability when allow_url_ open is enabled. This bug allows attackers to modify HTTP headers for outbound requests by injecting CRLF sequences into the arguments to the fopen and file methods.

affected-products-logoAffected Products

PHP 4.2.1 through 4.2.3

Impact logoImpact

Allows remote attackers to modify HTTP headers for outgoing requests.

recomended-action-logoRecommended Actions

Apply appropriate patch from the vendor or Upgrade to non-vulnerable version if available.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)