CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation70 reference(s) from NVD