CRLF injection vulnerability in the mail function in Dotdeb PHP before 5.2.0 Rev 3 allows remote attackers to bypass the protection scheme and inject arbitrary email headers via CRLF sequences in the query string, which is processed via the PHP_SELF variable.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Dotdeb_php | Dotdeb | 4.4 (including) | 4.4 (including) |
| Dotdeb_php | Dotdeb | 4.4.3 (including) | 4.4.3 (including) |
| Dotdeb_php | Dotdeb | 4.4.4 (including) | 4.4.4 (including) |
| Dotdeb_php | Dotdeb | 5.0 (including) | 5.0 (including) |
| Dotdeb_php | Dotdeb | 5.1 (including) | 5.1 (including) |
| Dotdeb_php | Dotdeb | 5.2 (including) | 5.2 (including) |