PT-2008-6676 · Php · Phpmyadmin

Michael Brooks

·

Publicado

2008-12-17

·

Atualizado

2017-09-29

·

CVE-2008-5621

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 2.11.x through 2.11.9.3 phpMyAdmin versions 3.x through 3.1.0.0
Description A cross-site request forgery (CSRF) issue allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to "tbl structure.php" with a modified table parameter. This can be leveraged to conduct SQL injection attacks and execute arbitrary code.
Recommendations For phpMyAdmin versions 2.11.x through 2.11.9.3, update to version 2.11.9.4 or later. For phpMyAdmin versions 3.x through 3.1.0.0, update to version 3.1.1.0 or later.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5621
DSA-1723-1

Produtos afetados

Phpmyadmin