CVE-2005-3883 PUBLISHED CVSS 5 MEDIUM

CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary e-mail headers via line feeds (LF) in the "To" address argument.

EPSS 3.15% · 86.8th percentile

Risk Scores

CVSS v2.0
5
EPSS Score
3.15%
86.8th percentile

Affected Products

VendorProductVersions
phpphp5.0.5, 4.0.6, 4.0.7
n/an/an/a

Timeline

References

…and 2 more

Open in Interactive Console →