CVE-2009-1149: Input Validation
CRLF injection vulnerability in bsdispasmimetype.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) ctype and possibly (2) filetype parameters.
Other sources
CRLF injection vulnerability in bsdispasmimetype.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) ctype and possibly (2) filetype parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/phpmyadmin/phpmyadminto a version that resolves this vulnerability.Fixed in 3.1.3.1
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1149?
CVE-2009-1149 has a moderate severity rating due to potential for HTTP response splitting attacks.
How do I fix CVE-2009-1149?
To fix CVE-2009-1149, upgrade phpMyAdmin to version 3.1.3.1 or later.
What versions are affected by CVE-2009-1149?
CVE-2009-1149 affects phpMyAdmin versions prior to 3.1.3.1, including 3.1.0, 3.1.1, and 3.1.2.
What type of vulnerability is CVE-2009-1149?
CVE-2009-1149 is a CRLF injection vulnerability that allows arbitrary HTTP header injection.
Can CVE-2009-1149 lead to data exposure?
Yes, exploitation of CVE-2009-1149 can lead to unauthorized data exposure and web application attacks.