CVE-2009-1149

phpMyAdmin < 3.1.3.1 - HTTP Response Splitting via BLOB Streaming CRLF Injection

Title source: llm
STIX 2.1

Description

CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) c_type and possibly (2) file_type parameters.

References (5)

Core 5
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34642
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34468
Patch, Vendor Advisory x_refsource_confirm
http://www.phpmyadmin.net/home_page/security/PMASA-2009-1.php

Scores

EPSS 0.0072
EPSS Percentile 72.6%

Details

CWE
CWE-20
Status published
Products (7)
phpmyadmin/phpmyadmin 3.1.0
phpmyadmin/phpmyadmin 3.1.0.0
phpmyadmin/phpmyadmin 3.1.1 (2 CPE variants)
phpmyadmin/phpmyadmin 3.1.2 (2 CPE variants)
phpmyadmin/phpmyadmin 3.1.3 rc1
phpmyadmin/phpmyadmin < 3.1.3
phpmyadmin/phpmyadmin 0 - 3.1.3.1Packagist
Published Mar 26, 2009
Tracked Since Feb 18, 2026