CVE-2009-1148

phpMyAdmin < 3.1.3.1 - Path Traversal via BLOB Streaming File Path Parameter

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable).

References (5)

Core 5
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34642
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34468
Patch, Vendor Advisory x_refsource_confirm
http://www.phpmyadmin.net/home_page/security/PMASA-2009-1.php

Scores

EPSS 0.0060
EPSS Percentile 69.6%

Details

CWE
CWE-22
Status published
Products (6)
phpmyadmin/phpmyadmin 3.1.0
phpmyadmin/phpmyadmin 3.1.0.0
phpmyadmin/phpmyadmin 3.1.1 (2 CPE variants)
phpmyadmin/phpmyadmin 3.1.2 (2 CPE variants)
phpmyadmin/phpmyadmin 3.1.3 rc1
phpmyadmin/phpmyadmin < 3.1.3
Published Mar 26, 2009
Tracked Since Feb 18, 2026