Description
CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
References (7)
Scores
EPSS
0.0257
EPSS Percentile
85.6%
Details
CWE
CWE-113
Status
published
Products (1)
drupal/drupal
4.7.0 - 4.7.8
Published
Oct 19, 2007
Tracked Since
Feb 18, 2026