Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-4605

Опубликовано: 19 янв. 2010
Источник: debian
EPSS Низкий

Описание

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phpmyadminfixed4:3.2.4-1package

Примечания

  • vulnerable code does not in the 3.x series (sid and squeeze checked)

  • http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin?view=rev&revision=13149

  • there is still at least one unserialize() call on _POST data

EPSS

Процентиль: 64%
0.0047
Низкий

Связанные уязвимости

ubuntu
больше 15 лет назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

redhat
больше 15 лет назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

nvd
больше 15 лет назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

github
около 3 лет назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

EPSS

Процентиль: 64%
0.0047
Низкий