Description
CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.
Remediation
References
Related Vulnerabilities
WordPress Plugin IGIT Posts Slider Widget TimThumb Arbitrary File Upload (1.1)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2015-4852)
WordPress Plugin Quick Contact Form Multiple Vulnerabilities (8.0.3.1)
WordPress Plugin rtMedia for WordPress, BuddyPress and bbPress Cross-Site Scripting (3.10.1)
WordPress Plugin xili-tidy-tags Cross-Site Request Forgery (1.12.03)