Input validation error in PHP - CVE-2002-1783

 

Input validation error in PHP - CVE-2002-1783

Published: July 11, 2017 / Updated: June 8, 2025


Vulnerability identifier: #VU110534
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2002-1783
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to corrupt data.

CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or (2) file functions.


Affected software

PHP

How to mitigate CVE-2002-1783

Install update from vendor's website.

PHP - update to 4.10

External References

Related Security Bulletins