PT-2010-1243 · Php · Phpmyadmin
Thijs Kinkhorst
·
Publicado
2010-01-19
·
Atualizado
2022-05-17
·
CVE-2008-7252
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
phpMyAdmin versions 2.11.x through 2.11.9
Description
The issue in
libraries/File.class.php involves the use of predictable filenames for temporary files, which has unknown impact and attack vectors. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.Recommendations
For phpMyAdmin versions 2.11.x through 2.11.9, update to version 2.11.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the
libraries/File.class.php file until a patch is applied.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phpmyadmin