First published: Thu Mar 26 2009(Updated: )
CRLF injection vulnerability in `bs_disp_as_mime_type.php` in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) `c_type` and possibly (2) `file_type` parameters.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | =3.1.2 | |
phpMyAdmin phpMyAdmin | =3.1.0 | |
phpMyAdmin phpMyAdmin | =3.1.1-rc1 | |
phpMyAdmin phpMyAdmin | =3.1.1 | |
phpMyAdmin phpMyAdmin | =3.1.3-rc1 | |
phpMyAdmin phpMyAdmin | =3.1.0.0 | |
phpMyAdmin phpMyAdmin | =3.1.2-rc1 | |
phpMyAdmin phpMyAdmin | <=3.1.3 | |
composer/phpmyadmin/phpmyadmin | <3.1.3.1 | 3.1.3.1 |
<=3.1.3 | ||
=3.1.0 | ||
=3.1.0.0 | ||
=3.1.1 | ||
=3.1.1-rc1 | ||
=3.1.2 | ||
=3.1.2-rc1 | ||
=3.1.3-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.