PT-2010-1243 · Php · Phpmyadmin
Thijs Kinkhorst
·
Published
2010-01-19
·
Updated
2022-05-17
·
CVE-2008-7252
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
phpMyAdmin versions 2.11.x through 2.11.9
Description
The issue in
libraries/File.class.php involves the use of predictable filenames for temporary files, which has unknown impact and attack vectors. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.Recommendations
For phpMyAdmin versions 2.11.x through 2.11.9, update to version 2.11.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the
libraries/File.class.php file until a patch is applied.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpmyadmin