CVE-2016-3166

MEDIUM

Drupal 6.x <6.38 - CRLF Injection

Title source: llm

Description

CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module that allows user-submitted data to appear in HTTP headers.

Scores

CVSS v3 5.9
EPSS 0.0050
EPSS Percentile 65.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Classification

Status draft

Affected Products (50)

debian/debian_linux
debian/debian_linux
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
... and 35 more

Timeline

Published Apr 12, 2016
Tracked Since Feb 18, 2026