Back

CVE-2002-1783

CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or (2) file functions.

Published: Dec 31, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (17)

Vendor Product Version
php php 3.0.14
php php 3.0.15
php php 3.0.16
php php 3.0.17
php php 3.0.18
php php 4.0.3
php php 4.0.4
php php 4.0.5
php php 4.0.6
php php 4.0.7
php php 4.1.0
php php 4.1.1
php php 4.1.2
php php 4.2.0
php php 4.2.1
php php 4.2.2
php php 4.2.3

GitHub Security Advisory GHSA-5mpg-wwpc-q4pq

CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 16.74%

Top 3% most likely to be exploited

Threat Score 25 / 100

Data Sources

NVD EPSS GitHub