Back to search
CVE-2008-3197
Published: Jul 16, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
MDVSA-2008:202
vendor-advisory
x_refsource_MANDRIVA
http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0
x_refsource_CONFIRM
SUSE-SR:2009:003
vendor-advisory
x_refsource_SUSE
FEDORA-2008-6502
vendor-advisory
x_refsource_FEDORA
phpmyadmin-multi-csrf(43846)
vdb-entry
x_refsource_XF
http://sourceforge.net/project/shownotes.php?release_id=613660
x_refsource_CONFIRM
http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-5
x_refsource_CONFIRM
[oss-security] 20080715 CVE request: phpmyadmin < 2.11.7.1
mailing-list
x_refsource_MLIST
FEDORA-2008-6450
vendor-advisory
x_refsource_FEDORA
DSA-1641
vendor-advisory
x_refsource_DEBIAN
33822
third-party-advisory
x_refsource_SECUNIA
ADV-2008-2116
vdb-entry
x_refsource_VUPEN
31097
third-party-advisory
x_refsource_SECUNIA
31115
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now