CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html
http://rhn.redhat.com/errata/RHSA-2007-0889.html
http://secunia.com/advisories/25187 Vendor Advisory
http://secunia.com/advisories/25191 Vendor Advisory
http://secunia.com/advisories/25255 Vendor Advisory
http://secunia.com/advisories/25318 Vendor Advisory
http://secunia.com/advisories/25365
http://secunia.com/advisories/25372
http://secunia.com/advisories/25445
http://secunia.com/advisories/25660
http://secunia.com/advisories/26048
http://secunia.com/advisories/26967
http://secunia.com/advisories/27351
http://security.gentoo.org/glsa/glsa-200705-19.xml
http://securityreason.com/securityalert/2672
http://support.avaya.com/elmodocs2/security/ASA-2007-231.htm
http://us2.php.net/releases/4_4_7.php
http://us2.php.net/releases/5_2_2.php
http://www.debian.org/security/2007/dsa-1295
http://www.debian.org/security/2007/dsa-1296
http://www.mandriva.com/security/advisories?name=MDKSA-2007:102
http://www.mandriva.com/security/advisories?name=MDKSA-2007:103
http://www.redhat.com/support/errata/RHSA-2007-0349.html
http://www.redhat.com/support/errata/RHSA-2007-0355.html
http://www.redhat.com/support/errata/RHSA-2007-0888.html
http://www.securityfocus.com/archive/1/463596/100/0/threaded
http://www.securityfocus.com/bid/23813
http://www.securityfocus.com/bid/23818 Patch
http://www.securitytracker.com/id?1018022
http://www.trustix.org/errata/2007/0017/
http://www.ubuntu.com/usn/usn-462-1
http://www.vupen.com/english/advisories/2007/2187
https://exchange.xforce.ibmcloud.com/vulnerabilities/34413
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10839
https://rhn.redhat.com/errata/RHSA-2007-0348.html
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2007-05-09T00:00:00

Updated: 2018-10-16T14:57:01

Reserved: 2007-05-07T00:00:00


Link: CVE-2007-2509

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2007-05-09T00:19:00.000

Modified: 2018-10-30T16:25:35.747


Link: CVE-2007-2509

JSON object: View

cve-icon Redhat Information

No data.

CWE