Lucene search

K
freebsdFreeBSD54F72962-C7BA-11DD-A721-0030843D3802
HistoryDec 09, 2008 - 12:00 a.m.

phpmyadmin -- cross-site request forgery vulnerability

2008-12-0900:00:00
vuxml.freebsd.org
17

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

EPSS

0.015

Percentile

87.1%

The phpMyAdmin Team reports:

A logged-in user can be subject of SQL injection through cross
site request forgery. Several scripts in phpMyAdmin are
vulnerable and the attack can be made through table parameter.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchphpmyadmin211< 2.11.9.4UNKNOWN
FreeBSDanynoarchphpmyadmin< 3.1.1UNKNOWN

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

EPSS

0.015

Percentile

87.1%