CVE-2006-1714

phpMyForum 4.0 - CRLF Injection

Title source: llm
STIX 2.1

Description

CRLF injection vulnerability in index.php in Christoph Roeder phpMyForum 4.0 allows remote attackers to inject HTTP headers via hex-encoded CRLF sequences in the type parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Psych0 · textwebappsphp
https://www.exploit-db.com/exploits/27586

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/430480/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17420
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/432455/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25750

Scores

EPSS 0.0317
EPSS Percentile 87.0%

Details

Status published
Products (1)
phpmyforum/phpmyforum 4.0
Published Apr 11, 2006
Tracked Since Feb 18, 2026