VDB
CVE-2005-3883
CVE-2005-3883
PUBLISHED
CVSS 5 MEDIUM
CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary e-mail headers via line feeds (LF) in the "To" address argument.
EPSS 3.05% · 86.3th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
3.05%
86.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| php | php | 4.1.2, 4.0.6, 4.0.7 |
| n/a | n/a | n/a |
Timeline
- Nov 29, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- http://www.php.net/release_5_1_0.php url
- http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm url
- TLSA-2006-38 vendor-advisory
- 18054 third-party-advisory
- 1015296 vdb
- MDKSA-2005:238 vendor-advisory
- 20951 third-party-advisory
- SUSE-SA:2005:069 vendor-advisory
- USN-232-1 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2005-3883 advisory
- https://www.ubuntu.com/usn/usn-232-1 url
- http://bugs.php.net/bug.php?id=35307 url
- http://secunia.com/advisories/17763 url
- http://secunia.com/advisories/18198 url
- http://secunia.com/advisories/19832 url
- http://www.securityfocus.com/bid/15571 url
- http://secunia.com/advisories/20210 technical
- ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc technical
- http://rhn.redhat.com/errata/RHSA-2006-0276.html technical
- http://www.vupen.com/english/advisories/2006/2685 technical
…and 2 more