CVE-2007-5595

Drupal <4.7.8, <5.3 - CRLF Injection

Title source: llm
STIX 2.1

Description

CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

Scores

EPSS 0.0257
EPSS Percentile 85.6%

Details

CWE
CWE-113
Status published
Products (1)
drupal/drupal 4.7.0 - 4.7.8
Published Oct 19, 2007
Tracked Since Feb 18, 2026