CVE-2007-2509: Input Validation
Published May 9, 2007
·Updated
CRLF injection vulnerability in the ftpputcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.
Affected Software
59 affected components
PHP PHP=4.3.9
PHP PHP=5.1.5
PHP PHP=5.1.2
PHP PHP=4.2.0
PHP PHP=5.1.1
PHP PHP=4.4.4
PHP PHP=4.1.0
PHP PHP=5.1.6
PHP PHP=4.3.4
PHP PHP=4.0.4
PHP PHP=4.3.0
PHP PHP=4.0.5
PHP PHP=5.0-rc1
PHP PHP=5.0.5
PHP PHP=4.3.6
PHP PHP=5.0.1
PHP PHP=5.1.4
PHP PHP=4.0.7-rc2
PHP PHP=4.3.7
PHP PHP=5.0.4
PHP PHP=4.0.7-rc1
PHP PHP=4.2.2
PHP PHP=4.4.2
PHP PHP=4.3.2
PHP PHP=4.3.11
PHP PHP=4.0.0
PHP PHP=4.0.3-patch1
PHP PHP=4.0.7
PHP PHP=4.0.2
PHP PHP=4.3.3
PHP PHP=5.0-rc3
PHP PHP=4.1.1
PHP PHP=4.4.3
PHP PHP=5.0.3
PHP PHP=4.2.3
PHP PHP=5.1.0
PHP PHP=4.4.5
PHP PHP=4.0.1-patch1
PHP PHP=4.0.1-patch2
PHP PHP=4.0.6
PHP PHP=5.2.0
PHP PHP=5.0-rc2
PHP PHP=4.1.2
PHP PHP=4.0.7-rc3
PHP PHP=4.3.1
PHP PHP=5.1.3
PHP PHP=4.4.0
PHP PHP=4.3.10
PHP PHP=4.2.1
PHP PHP=4.0.4-patch1
PHP PHP=4.0.1
PHP PHP=5.0.2
PHP PHP=4.4.6
PHP PHP=4.4.1
PHP PHP=5.2.1
PHP PHP=4.0.3
PHP PHP=5.0.0
PHP PHP=4.3.8
PHP PHP=4.3.5
Remediation
Patch Available
Event History
May 9, 2007
CVE Published
12:19 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2509?
CVE-2007-2509 is considered to have a medium severity due to its potential for exploitation through CRLF injection.
2
How do I fix CVE-2007-2509?
To fix CVE-2007-2509, upgrade to PHP version 4.4.7 or later, or 5.2.2 or later.
3
What software versions are affected by CVE-2007-2509?
CVE-2007-2509 affects PHP versions prior to 4.4.7 and 5.x versions before 5.2.2.
4
What is CVE-2007-2509?
CVE-2007-2509 is a CRLF injection vulnerability in the ftp_putcmd function in specific PHP versions allowing remote command injection.
5
Can CVE-2007-2509 be exploited remotely?
Yes, CVE-2007-2509 can be exploited remotely if the attacker can send specially crafted FTP commands.