Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) c_type and possibly (2) file_type parameters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpMyAdmin BLOB Streaming 多个输入验证漏洞
Vulnerability Description
phpMyAdmin是一个免费的MySQL数据管理工具软件,PHP写的旨在处理在万维网和操作MySQL。 phpMyAdmin支持广泛的MySQL管理操作(管理数据库,表,字段,关系,索引,用户,权限,等等),并可以直接执行任何SQL语句。 phpMyAdmin 3.1.3.1版本之前的版本的BLOB流动特性的bs_disp_as_mime_type.php中存在CRLF注入漏洞。远程攻击者可以借助(1)c_type及其可能的(2)file_type参数,注入任意HTTP页眉并执行HTTP响应分裂攻击。
CVSS Information
N/A
Vulnerability Type
N/A