CVE-2002-1783

PHP 4.2.1-4.2.3 - CRLF Injection via fopen or file Functions

Title source: llm
STIX 2.1

Description

CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or (2) file functions.

References (5)

Core 5
Core References
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5681
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/10080
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2002/dsa-168
Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-09/0086.html

Scores

EPSS 0.0115
EPSS Percentile 78.8%

Details

Status published
Products (17)
php/php 3.0.14
php/php 3.0.15
php/php 3.0.16
php/php 3.0.17
php/php 3.0.18
php/php 4.0.3
php/php 4.0.4
php/php 4.0.5
php/php 4.0.6
php/php 4.0.7
... and 7 more
Published Dec 31, 2002
Tracked Since Feb 18, 2026