CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module that allows user-submitted data to appear in HTTP headers.
{
"cwe_ids": [
"CWE-113"
],
"github_reviewed": true,
"github_reviewed_at": "2024-04-23T22:29:18Z",
"nvd_published_at": "2016-04-12T15:59:00Z",
"severity": "MODERATE"
}