Back

MEDIUM

phpMyAdmin: SQL injection through XSRF on several pages (PMASA-2008-10)

Published Dec 17, 2008

Description

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 17, 2008
Updated Aug 7, 2024
Reserved Dec 16, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a