CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or (2) file functions.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2005-06-28T04:00:00

Updated: 2017-07-10T14:57:01

Reserved: 2005-06-29T00:00:00


Link: CVE-2002-1783

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2002-12-31T05:00:00.000

Modified: 2017-07-11T01:29:25.633


Link: CVE-2002-1783

JSON object: View

cve-icon Redhat Information

No data.