Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-1567

Опубликовано: 31 мар. 2008
Источник: debian
EPSS Низкий

Описание

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phpmyadminfixed2.11.5.1package

Примечания

  • https://www.phpmyadmin.net/security/PMASA-2008-2/

  • https://github.com/phpmyadmin/phpmyadmin/commit/533bb88e32aafc17e754e5ea5e26e9b02b306993

  • It is a workaround for the limited security that PHP has for

  • session files on a shared host. This limitation is documented with

  • PHP, warned against and not a specific vulnerability in phpMyAdmin.

  • I hence consider it a security enhancement/feature, not a vulnerability.

EPSS

Процентиль: 12%
0.0004
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 17 лет назад

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

CVSS3: 5.5
nvd
около 17 лет назад

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

CVSS3: 5.5
github
около 3 лет назад

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

EPSS

Процентиль: 12%
0.0004
Низкий