Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-1149

Опубликовано: 04 мар. 2008
Источник: debian
EPSS Низкий

Описание

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phpmyadminfixed4:2.11.5-1package
phpmyadminno-dsaetchpackage
phpmyadminnot-affectedsargepackage

Примечания

  • https://www.phpmyadmin.net/security/PMASA-2008-1/

  • https://github.com/phpmyadmin/phpmyadmin/commit/c57b39bed91f06d574a95d8a5a091e5e59492d69

  • SQL injection if you can set local cookies, which means

  • you must be able to create pages in the same cookie domain, which seems

  • rare and unwise. low priority.

EPSS

Процентиль: 72%
0.00764
Низкий

Связанные уязвимости

ubuntu
больше 17 лет назад

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

redhat
больше 17 лет назад

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

nvd
больше 17 лет назад

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

github
около 3 лет назад

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

EPSS

Процентиль: 72%
0.00764
Низкий