{"id":"CVE-2017-1000247","aliases":[],"url":"https://o3.security/vulnerability/CVE-2017-1000247","summary":"British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Apache resulting in HTTP Header Injection flaws.","details":"British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Apache resulting in HTTP Header Injection flaws.","published":"2017-11-17T04:29:00.547","modified":"2026-06-17T00:58:58.633","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://www.codeigniter.com/userguide3/changelog.html#version-3-1-4"},{"type":"ADVISORY","url":"https://www.codeigniter.com/userguide3/changelog.html#version-3-1-4"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T00:58:58.633"}}