VDB

CVE-2007-2509

CVE-2007-2509 PUBLISHED

Reported by mitre · Published May 9, 2007

CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.

Affected Products

VendorProductVersions
n/an/an/a
n/an/a*, n/a, n/a

Timeline

  • May 9, 2007 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 3, 2022 EPSS Score
  • Dec 17, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Apr 1, 2023 EPSS Score
  • May 24, 2023 EPSS Score
  • Sep 6, 2023 EPSS Score
  • Oct 28, 2023 EPSS Score
  • Feb 10, 2024 EPSS Score

References

…and 15 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›