CVE-2009-1149

Source
https://nvd.nist.gov/vuln/detail/CVE-2009-1149
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2009-1149.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2009-1149
Aliases
Published
2009-03-26T14:30:00Z
Modified
2024-09-18T01:00:21Z
Summary
[none]
Details

CRLF injection vulnerability in bsdispasmimetype.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) ctype and possibly (2) filetype parameters.

References

Affected packages

Debian:11 / phpmyadmin

Package

Name
phpmyadmin
Purl
pkg:deb/debian/phpmyadmin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:3.1.3.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / phpmyadmin

Package

Name
phpmyadmin
Purl
pkg:deb/debian/phpmyadmin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:3.1.3.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / phpmyadmin

Package

Name
phpmyadmin
Purl
pkg:deb/debian/phpmyadmin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:3.1.3.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}