PT-2008-3126 · Mysql Server · Phpmyadmin

Jim Hermann

·

Published

2008-03-31

·

Updated

2024-02-14

·

CVE-2008-1567

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions prior to 2.11.5.1
Description The issue allows local users to obtain sensitive information, including the MySQL username, password, and the Blowfish secret key, which are stored in cleartext in a Session file under /tmp.
Recommendations For versions prior to 2.11.5.1, update to version 2.11.5.1 or later to resolve the issue.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2008-1567
DSA-1557-1

Affected Products

Phpmyadmin