AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-1149

HIGH · CVSS 7.5 EPSS 1.43%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-03-26 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-1149
Severity
HIGH
CVSS
7.5
EPSS
1.43%

Original NVD Description

CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) c_type and possibly (2) file_type parameters.