Back

MEDIUM

phpMyAdmin: user/password/secret key are stored plaintext

Published Mar 31, 2008

Description

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 31, 2008
Updated Aug 7, 2024
Reserved Mar 31, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a