CVE
- Id
- 25866
- CVE No.
- CVE-2007-2509
- Status
- Candidate
- Description
- CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.
- Phase
- Assigned (20070507)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 259640 | 25866 | CVE-2007-2509 | BUGTRAQ:20070323 CRLF injection in PHP ftp function | View |
| 259641 | 25866 | CVE-2007-2509 | URL:http://www.securityfocus.com/archive/1/archive/1/463596/100/0/threaded | View |
| 259642 | 25866 | CVE-2007-2509 | CONFIRM:http://us2.php.net/releases/4_4_7.php | View |
| 259643 | 25866 | CVE-2007-2509 | CONFIRM:http://us2.php.net/releases/5_2_2.php | View |
| 259644 | 25866 | CVE-2007-2509 | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2007-231.htm | View |
| 259645 | 25866 | CVE-2007-2509 | DEBIAN:DSA-1295 | View |
| 259646 | 25866 | CVE-2007-2509 | URL:http://www.debian.org/security/2007/dsa-1295 | View |
| 259647 | 25866 | CVE-2007-2509 | DEBIAN:DSA-1296 | View |
| 259648 | 25866 | CVE-2007-2509 | URL:http://www.debian.org/security/2007/dsa-1296 | View |
| 259649 | 25866 | CVE-2007-2509 | GENTOO:GLSA-200705-19 | View |
| 259650 | 25866 | CVE-2007-2509 | URL:http://security.gentoo.org/glsa/glsa-200705-19.xml | View |
| 259651 | 25866 | CVE-2007-2509 | MANDRIVA:MDKSA-2007:102 | View |
| 259652 | 25866 | CVE-2007-2509 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:102 | View |
| 259653 | 25866 | CVE-2007-2509 | MANDRIVA:MDKSA-2007:103 | View |
| 259654 | 25866 | CVE-2007-2509 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:103 | View |
| 259655 | 25866 | CVE-2007-2509 | REDHAT:RHSA-2007:0348 | View |
| 259656 | 25866 | CVE-2007-2509 | URL:https://rhn.redhat.com/errata/RHSA-2007-0348.html | View |
| 259657 | 25866 | CVE-2007-2509 | REDHAT:RHSA-2007:0349 | View |
| 259658 | 25866 | CVE-2007-2509 | URL:http://www.redhat.com/support/errata/RHSA-2007-0349.html | View |
| 259659 | 25866 | CVE-2007-2509 | REDHAT:RHSA-2007:0355 | View |
| 259660 | 25866 | CVE-2007-2509 | URL:http://www.redhat.com/support/errata/RHSA-2007-0355.html | View |
| 259661 | 25866 | CVE-2007-2509 | REDHAT:RHSA-2007:0889 | View |
| 259662 | 25866 | CVE-2007-2509 | URL:http://rhn.redhat.com/errata/RHSA-2007-0889.html | View |
| 259663 | 25866 | CVE-2007-2509 | REDHAT:RHSA-2007:0888 | View |
| 259664 | 25866 | CVE-2007-2509 | URL:http://www.redhat.com/support/errata/RHSA-2007-0888.html | View |
| 259665 | 25866 | CVE-2007-2509 | SUSE:SUSE-SA:2007:044 | View |
| 259666 | 25866 | CVE-2007-2509 | URL:http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html | View |
| 259667 | 25866 | CVE-2007-2509 | TRUSTIX:2007-0017 | View |
| 259668 | 25866 | CVE-2007-2509 | URL:http://www.trustix.org/errata/2007/0017/ | View |
| 259669 | 25866 | CVE-2007-2509 | UBUNTU:USN-462-1 | View |
| 259670 | 25866 | CVE-2007-2509 | URL:http://www.ubuntu.com/usn/usn-462-1 | View |
| 259671 | 25866 | CVE-2007-2509 | BID:23818 | View |
| 259672 | 25866 | CVE-2007-2509 | URL:http://www.securityfocus.com/bid/23818 | View |
| 259673 | 25866 | CVE-2007-2509 | BID:23813 | View |
| 259674 | 25866 | CVE-2007-2509 | URL:http://www.securityfocus.com/bid/23813 | View |
| 259675 | 25866 | CVE-2007-2509 | OVAL:oval:org.mitre.oval:def:10839 | View |
| 259676 | 25866 | CVE-2007-2509 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10839 | View |
| 259677 | 25866 | CVE-2007-2509 | VUPEN:ADV-2007-2187 | View |
| 259678 | 25866 | CVE-2007-2509 | URL:http://www.vupen.com/english/advisories/2007/2187 | View |
| 259679 | 25866 | CVE-2007-2509 | SECTRACK:1018022 | View |
| 259680 | 25866 | CVE-2007-2509 | URL:http://www.securitytracker.com/id?1018022 | View |
| 259681 | 25866 | CVE-2007-2509 | SECUNIA:25187 | View |
| 259682 | 25866 | CVE-2007-2509 | URL:http://secunia.com/advisories/25187 | View |
| 259683 | 25866 | CVE-2007-2509 | SECUNIA:25191 | View |
| 259684 | 25866 | CVE-2007-2509 | URL:http://secunia.com/advisories/25191 | View |
| 259685 | 25866 | CVE-2007-2509 | SECUNIA:25318 | View |
| 259686 | 25866 | CVE-2007-2509 | URL:http://secunia.com/advisories/25318 | View |
| 259687 | 25866 | CVE-2007-2509 | SECUNIA:25255 | View |
| 259688 | 25866 | CVE-2007-2509 | URL:http://secunia.com/advisories/25255 | View |
| 259689 | 25866 | CVE-2007-2509 | SECUNIA:25365 | View |
| 259690 | 25866 | CVE-2007-2509 | URL:http://secunia.com/advisories/25365 | View |
| 259691 | 25866 | CVE-2007-2509 | SECUNIA:25372 | View |
| 259692 | 25866 | CVE-2007-2509 | URL:http://secunia.com/advisories/25372 | View |
| 259693 | 25866 | CVE-2007-2509 | SECUNIA:25445 | View |
| 259694 | 25866 | CVE-2007-2509 | URL:http://secunia.com/advisories/25445 | View |
| 259695 | 25866 | CVE-2007-2509 | SECUNIA:25660 | View |
| 259696 | 25866 | CVE-2007-2509 | URL:http://secunia.com/advisories/25660 | View |
| 259697 | 25866 | CVE-2007-2509 | SECUNIA:26048 | View |
| 259698 | 25866 | CVE-2007-2509 | URL:http://secunia.com/advisories/26048 | View |
| 259699 | 25866 | CVE-2007-2509 | SECUNIA:26967 | View |
| 259700 | 25866 | CVE-2007-2509 | URL:http://secunia.com/advisories/26967 | View |
| 259701 | 25866 | CVE-2007-2509 | SECUNIA:27351 | View |
| 259702 | 25866 | CVE-2007-2509 | URL:http://secunia.com/advisories/27351 | View |
| 259703 | 25866 | CVE-2007-2509 | SREASON:2672 | View |
| 259704 | 25866 | CVE-2007-2509 | URL:http://securityreason.com/securityalert/2672 | View |
| 259705 | 25866 | CVE-2007-2509 | XF:php-ftpputcmd-crlf-injection(34413) | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 51702 | JVNDB-2007-000365 | PHP の user_filter_factory_create() 関数におけるバッファオーバーフローの脆弱性 | PHP の user_filter_factory_create() 関数には、バッファオーバーフローの脆弱性が存在します。本脆弱性の詳細は不明です。 | CVE-2007-2511 | 25866 | 7.2 | http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-000365.html | View |