Vulnerability Description
Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpmyadmin | Phpmyadmin | <= 3.1.3 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html
- http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_3_1_3/php
- http://secunia.com/advisories/34468
- http://secunia.com/advisories/34642
- http://www.phpmyadmin.net/home_page/security/PMASA-2009-1.phpPatchVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html
- http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_3_1_3/php
- http://secunia.com/advisories/34468
- http://secunia.com/advisories/34642
- http://www.phpmyadmin.net/home_page/security/PMASA-2009-1.phpPatchVendor Advisory
FAQ
What is CVE-2009-1148?
CVE-2009-1148 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequenc...
How severe is CVE-2009-1148?
CVE-2009-1148 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-1148?
Check the references section above for vendor advisories and patch information. Affected products include: Phpmyadmin Phpmyadmin.