CVE-2007-2509

PHP <4.4.7, <5.2.2 - Code Injection

Title source: llm
STIX 2.1

Description

CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.

References (35)

Core 35
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25660
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:103
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25187
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25191
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-462-1
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2187
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0888.html
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:102
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26048
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2007/dsa-1296
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0355.html
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200705-19.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26967
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27351
Vendor Advisory vendor-advisory x_refsource_trustix
http://www.trustix.org/errata/2007/0017/
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23818
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23813
Release Notes x_refsource_confirm
http://us2.php.net/releases/4_4_7.php
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0349.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2007/dsa-1295
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25318
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34413
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/463596/100/0/threaded
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2007-0889.html
Release Notes x_refsource_confirm
http://us2.php.net/releases/5_2_2.php
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25365
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2672
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25255
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25445
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25372
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10839
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018022
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2007-0348.html

Scores

EPSS 0.0629
EPSS Percentile 91.0%

Details

CWE
CWE-20
Status published
Products (41)
php/php 4.0.0
php/php 4.0.1 (3 CPE variants)
php/php 4.0.2
php/php 4.0.3 (2 CPE variants)
php/php 4.0.4 (2 CPE variants)
php/php 4.0.5
php/php 4.0.6
php/php 4.0.7 (4 CPE variants)
php/php 4.1.0
php/php 4.1.1
... and 31 more
Published May 09, 2007
Tracked Since Feb 18, 2026