CVE-2007-5595: CRLF Injection
CRLF injection vulnerability in the drupalgoto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5595?
CVE-2007-5595 is classified as a high severity vulnerability due to its potential for HTTP response splitting attacks.
How do I fix CVE-2007-5595?
To fix CVE-2007-5595, upgrade Drupal to version 4.7.8 or 5.3 or later where the vulnerability has been patched.
Which versions of Drupal are affected by CVE-2007-5595?
CVE-2007-5595 affects Drupal versions 4.7.0 through 4.7.7 and 5.0 through 5.2.
What type of attack does CVE-2007-5595 allow?
CVE-2007-5595 allows attackers to conduct HTTP response splitting attacks by injecting arbitrary HTTP headers.
Can CVE-2007-5595 be exploited remotely?
Yes, CVE-2007-5595 can be exploited by remote attackers due to the nature of the CRLF injection vulnerability.