CVE-2007-4464 describes a CRLF injection vulnerability in the Fileinfo 2.0.9 plugin for Total Commander, affecting both fransois_gannier and ghisler versions of the plugin and Total Commander. An attacker can exploit this by embedding CRLF sequences within the IMAGE_EXPORT_DIRECTORY array of a crafted PE file, which, when processed by the plugin, can spoof information in the Image File Header tab. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and potential for partial integrity impact, specifically complicating forensic investigations. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.09CPE matchmatch criteria | cpe:2.3:a:fransois_gannier:fileinfo_plugin:2.09:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:ghisler:total_commander:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.