phpMyAdmin HTTP Response Splitting Vulnerability
High severity
GitHub Reviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Jan 23, 2024
Description
Published by the National Vulnerability Database
Mar 26, 2009
Published to the GitHub Advisory Database
May 2, 2022
Reviewed
Jan 23, 2024
Last updated
Jan 23, 2024
CRLF injection vulnerability in
bs_disp_as_mime_type.php
in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1)c_type
and possibly (2)file_type
parameters.References