Lucene search

K
osvGoogleOSV:GHSA-XRPQ-63MP-9VCW
HistoryMay 02, 2022 - 3:22 a.m.

phpMyAdmin HTTP Response Splitting Vulnerability

2022-05-0203:22:03
Google
osv.dev
9
phpmyadmin
blob streaming
crlf injection

AI Score

7.1

Confidence

Low

EPSS

0.011

Percentile

84.6%

CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) c_type and possibly (2) file_type parameters.

AI Score

7.1

Confidence

Low

EPSS

0.011

Percentile

84.6%