CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) c_type and possibly (2) file_type parameters.
| Software | From | Fixed in |
|---|---|---|
phpmyadmin / phpmyadmin
|
3.1.2 | 3.1.2.x |
phpmyadmin / phpmyadmin
|
3.1.0 | 3.1.0.x |
phpmyadmin / phpmyadmin
|
3.1.1-rc1 | 3.1.1-rc1.x |
phpmyadmin / phpmyadmin
|
3.1.1 | 3.1.1.x |
phpmyadmin / phpmyadmin
|
3.1.3-rc1 | 3.1.3-rc1.x |
phpmyadmin / phpmyadmin
|
3.1.0.0 | 3.1.0.0.x |
phpmyadmin / phpmyadmin
|
3.1.2-rc1 | 3.1.2-rc1.x |
phpmyadmin / phpmyadmin
|
- | 3.1.3.x |