Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-1398

29
FAUCET Score

CVE-2011-1398 describes an HTTP response-splitting vulnerability in PHP versions before 5.3.11 and 5.4.x before 5.4.0RC2. The sapi_header_op function fails to properly sanitize carriage return characters (%0D), allowing remote attackers to bypass HTTP response-splitting protections. This vulnerability, related to the interaction between the PHP header function and certain browsers like Internet Explorer and Google Chrome, could lead to content injection or other malicious activities. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack vector with medium complexity and potential for partial integrity impact (AV:N/AC:M/I:P). While not actively exploited in the wild (KEV: No), an ExploitDB entry (EDB-37688) confirms the existence of exploit code for HTTP header injection. Despite the availability of exploit code, there is no evidence of active exploitation, and community discussion and media coverage are minimal, suggesting low public awareness or impact. The EPSS score is low, further indicating a low probability of exploitation in the wild.

Impacted Technologies

VendorProductVersion(s)CPE
<= 5.3.10CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
5.3.0CPE matchmatch criteria
cpe:2.3:a:php:php:5.3.0:*:*:*:*:*:*:*
5.3.1CPE matchmatch criteria
cpe:2.3:a:php:php:5.3.1:*:*:*:*:*:*:*
5.3.2CPE matchmatch criteria
cpe:2.3:a:php:php:5.3.2:*:*:*:*:*:*:*
5.3.3CPE matchmatch criteria
cpe:2.3:a:php:php:5.3.3:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
10.17%
Probability of exploitation in next 30 days
EPSS Percentile
95.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-37688 · Oct 6, 2011
This CVE's current EPSS score of 0.1017 is in the 95th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: php53-0:5.3.3-21.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: php-0:5.1.6-43.el5_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: php-0:5.3.3-22.el6
View patch

Vendor Advisories (1)

redhatCVE-2011-1398Moderate

PHP: sapi_header_op() %0D sequence handling security bypass

Nov 6, 2011

References

article.gmane.org / gmane.comp.php.devel/70584
lists.opensuse.org / opensuse-security-announce/2013-08/msg00006.html
openwall.com / lists/oss-security/2012/08/29/5
openwall.com / lists/oss-security/2012/09/05/15
rhn.redhat.com / errata/RHSA-2013-1307.html
bugs.php.net / bug.php
secunia.com / advisories/55078
security-tracker.debian.org / tracker/CVE-2011-1398
securitytracker.com / id
ubuntu.com / usn/USN-1569-1