CVE-2007-2509

LOW

Description

CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.

References

http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html

http://rhn.redhat.com/errata/RHSA-2007-0889.html

http://secunia.com/advisories/25187

http://secunia.com/advisories/25191

http://secunia.com/advisories/25255

http://secunia.com/advisories/25318

http://secunia.com/advisories/25365

http://secunia.com/advisories/25372

http://secunia.com/advisories/25445

http://secunia.com/advisories/25660

http://secunia.com/advisories/26048

http://secunia.com/advisories/26967

http://secunia.com/advisories/27351

http://security.gentoo.org/glsa/glsa-200705-19.xml

http://securityreason.com/securityalert/2672

http://support.avaya.com/elmodocs2/security/ASA-2007-231.htm

http://us2.php.net/releases/4_4_7.php

http://us2.php.net/releases/5_2_2.php

http://www.debian.org/security/2007/dsa-1295

http://www.debian.org/security/2007/dsa-1296

http://www.mandriva.com/security/advisories?name=MDKSA-2007:102

http://www.mandriva.com/security/advisories?name=MDKSA-2007:103

http://www.redhat.com/support/errata/RHSA-2007-0349.html

http://www.redhat.com/support/errata/RHSA-2007-0355.html

http://www.redhat.com/support/errata/RHSA-2007-0888.html

http://www.securityfocus.com/archive/1/463596/100/0/threaded

http://www.securityfocus.com/bid/23813

http://www.securityfocus.com/bid/23818

http://www.securitytracker.com/id?1018022

http://www.trustix.org/errata/2007/0017/

http://www.ubuntu.com/usn/usn-462-1

http://www.vupen.com/english/advisories/2007/2187

https://exchange.xforce.ibmcloud.com/vulnerabilities/34413

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10839

https://rhn.redhat.com/errata/RHSA-2007-0348.html

Details

Source: MITRE

Published: 2007-05-09

Updated: 2018-10-30

Type: CWE-20

Risk Information

CVSS v2.0

Base Score: 2.6

Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 4.9

Severity: LOW

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:php:php:4.0.0:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.1:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.1:patch1:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.1:patch2:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.2:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.3:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.3:patch1:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.4:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.4:patch1:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.5:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.6:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.7:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.7:rc1:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.7:rc2:*:*:*:*:*:*

cpe:2.3:a:php:php:4.0.7:rc3:*:*:*:*:*:*

cpe:2.3:a:php:php:4.1.0:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.1.1:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.1.2:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.2.0:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.2.1:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.2.2:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.2.3:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.0:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.1:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.2:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.3:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.4:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.5:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.6:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.7:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.8:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.9:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.10:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.3.11:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.0:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.1:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.2:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.3:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.4:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.5:*:*:*:*:*:*:*

cpe:2.3:a:php:php:4.4.6:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0:rc1:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0:rc2:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0:rc3:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.0:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.1:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.2:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.3:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.4:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.0.5:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.2:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.3:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.4:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.5:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.1.6:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*

cpe:2.3:a:php:php:5.2.1:*:*:*:*:*:*:*

Tenable Plugins

View all (23 total)

IDNameProductFamilySeverity
78215F5 Networks BIG-IP : Multiple PHP vulnerabilities (SOL7859)NessusF5 Networks Local Security Checks
high
67569Oracle Linux 3 : php (ELSA-2007-0889)NessusOracle Linux Local Security Checks
high
67497Oracle Linux 4 : php (ELSA-2007-0349)NessusOracle Linux Local Security Checks
high
67496Oracle Linux 5 : php (ELSA-2007-0348)NessusOracle Linux Local Security Checks
high
67050CentOS 4 : php (CESA-2007:0349)NessusCentOS Local Security Checks
high
60257Scientific Linux Security Update : php on SL3.x i386/x86_64NessusScientific Linux Local Security Checks
high
29552SuSE 10 Security Update : PHP5 (ZYPP Patch Number 3754)NessusSuSE Local Security Checks
high
28062Ubuntu 6.06 LTS / 6.10 / 7.04 : php5 vulnerabilities (USN-462-1)NessusUbuntu Local Security Checks
high
27564RHEL 2.1 : php (RHSA-2007:0888)NessusRed Hat Local Security Checks
medium
27392openSUSE 10 Security Update : php5 (php5-3753)NessusSuSE Local Security Checks
high
27391openSUSE 10 Security Update : php5 (php5-3745)NessusSuSE Local Security Checks
high
26204CentOS 3 : php (CESA-2007:0889)NessusCentOS Local Security Checks
high
26191RHEL 3 : php (RHSA-2007:0889)NessusRed Hat Local Security Checks
high
25340GLSA-200705-19 : PHP: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
25334RHEL 5 : php (RHSA-2007:0348)NessusRed Hat Local Security Checks
high
25300Debian DSA-1296-1 : php4 - missing input sanitisingNessusDebian Local Security Checks
low
25299Debian DSA-1295-1 : php5 - several vulnerabilitiesNessusDebian Local Security Checks
medium
25212Mandrake Linux Security Advisory : php (MDKSA-2007:102)NessusMandriva Local Security Checks
high
25206CentOS 5 : php (CESA-2007:0348)NessusCentOS Local Security Checks
high
25193RHEL 4 : php (RHSA-2007:0349)NessusRed Hat Local Security Checks
high
3982PHP 4.x < 4.4.7 / 5.x < 5.2.2 Multiple VulnerabilitiesNessus Network MonitorWeb Servers
high
25159PHP < 4.4.7 / 5.2.2 Multiple VulnerabilitiesNessusCGI abuses
high
801085PHP < 4.4.7 / 5.2.2 Multiple VulnerabilitiesLog Correlation EngineWeb Servers
high