CVE Database
/

CVE-2006-5116

Back to search

CVE-2006-5116

Published: Oct 2, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdmin before 2.9.1-rc1 allow remote attackers to perform unauthorized actions as another user by (1) directly setting a token in the URL though dynamic variable evaluation and (2) unsetting arbitrary variables via the _REQUEST array, related to (a) libraries/common.lib.php, (b) session.inc.php, and (c) url_generating.lib.php. NOTE: the PHP unset function vector is covered by CVE-2006-3017.

VendorProductVersions

n/a

n/a

affected
n/a

References

22126
third-party-advisory
x_refsource_SECUNIA
20253
vdb-entry
x_refsource_BID
DSA-1207
vendor-advisory
x_refsource_DEBIAN
22781
third-party-advisory
x_refsource_SECUNIA
phpmyadmin-multiple-csrf(29301)
vdb-entry
x_refsource_XF
1677
third-party-advisory
x_refsource_SREASON
23086
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2006:071
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now