Oval Definition:oval:org.mitre.oval:def:8041
Revision Date:2015-02-23Version:20
Title:DSA-1557 phpmyadmin -- insufficient input sanitising
Description:Several remote vulnerabilities have been discovered in phpMyAdmin, an application to administrate MySQL over the WWW. The Common Vulnerabilities and Exposures project identifies the following problems: Attackers with CREATE table permissions were allowed to read arbitrary files readable by the webserver via a crafted HTTP POST request. The PHP session data file stored the username and password of a logged in user, which in some setups can be read by a local user. Cross site scripting and SQL injection were possible by attackers that had permission to create cookies in the same cookie domain as phpMyAdmin runs in.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-1149
CVE-2008-1567
CVE-2008-1924
DSA-1557
Platform(s):Debian GNU/Linux 4.0
Product(s):phpmyadmin
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Installed architecture is all
  • AND phpmyadmin is earlier than 4:2.9.1.1-7
  • BACK