Back
CVE-2002-1783
CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or (2) file functions.
Published: Dec 31, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (17)
| Vendor | Product | Version |
|---|---|---|
| php | php | 3.0.14 |
| php | php | 3.0.15 |
| php | php | 3.0.16 |
| php | php | 3.0.17 |
| php | php | 3.0.18 |
| php | php | 4.0.3 |
| php | php | 4.0.4 |
| php | php | 4.0.5 |
| php | php | 4.0.6 |
| php | php | 4.0.7 |
| php | php | 4.1.0 |
| php | php | 4.1.1 |
| php | php | 4.1.2 |
| php | php | 4.2.0 |
| php | php | 4.2.1 |
| php | php | 4.2.2 |
| php | php | 4.2.3 |
GitHub Security Advisory GHSA-5mpg-wwpc-q4pq
CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows...
References (10)
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0086.html Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0132.html Patch
- http://www.debian.org/security/2002/dsa-168 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/5681 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10080
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0086.html Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0132.html Patch
- http://www.debian.org/security/2002/dsa-168 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/5681 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10080
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
16.74%
Top 3% most likely to be exploited
Threat Score
25 / 100
Data Sources
NVD
EPSS
GitHub