CRLF injection vulnerability in the mail function in Dotdeb PHP before 5.2.0 Rev 3 allows remote attackers to bypass the protection scheme and inject arbitrary email headers via CRLF sequences in the query string, which is processed via the PHP_SELF variable.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dotdeb_php | Dotdeb | 4.4 (including) | 4.4 (including) |
Dotdeb_php | Dotdeb | 4.4.3 (including) | 4.4.3 (including) |
Dotdeb_php | Dotdeb | 4.4.4 (including) | 4.4.4 (including) |
Dotdeb_php | Dotdeb | 5.0 (including) | 5.0 (including) |
Dotdeb_php | Dotdeb | 5.1 (including) | 5.1 (including) |
Dotdeb_php | Dotdeb | 5.2 (including) | 5.2 (including) |