Vulnerability Name: | CVE-2008-1149 (CCN-40968) | ||||||||||||||||||||
Assigned: | 2008-03-01 | ||||||||||||||||||||
Published: | 2008-03-01 | ||||||||||||||||||||
Updated: | 2017-08-08 | ||||||||||||||||||||
Summary: | phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies. | ||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P) 4.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
6.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-89 CWE-352 | ||||||||||||||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2008-1149 Source: SUSE Type: UNKNOWN SUSE-SR:2008:026 Source: SUSE Type: UNKNOWN SUSE-SR:2009:003 Source: SECUNIA Type: Vendor Advisory 29143 Source: CCN Type: SA29200 phpMyAdmin "$_REQUEST" SQL Injection Vulnerability Source: SECUNIA Type: Vendor Advisory 29200 Source: SECUNIA Type: Vendor Advisory 29287 Source: SECUNIA Type: Vendor Advisory 29964 Source: SECUNIA Type: Vendor Advisory 30816 Source: SECUNIA Type: Vendor Advisory 32834 Source: SECUNIA Type: Vendor Advisory 33822 Source: DEBIAN Type: Patch DSA-1557 Source: DEBIAN Type: DSA-1557 phpmyadmin -- insufficient input sanitising Source: CCN Type: GLSA-200803-15 phpMyAdmin: SQL injection vulnerability Source: GENTOO Type: UNKNOWN GLSA-200803-15 Source: MANDRIVA Type: UNKNOWN MDVSA-2008:131 Source: CCN Type: OSVDB ID: 43051 phpMyAdmin Crafted Cookie $_REQUEST Superglobal Overwrite Source: CCN Type: phpMyAdmin security announcement PMASA-2008-1 SQL injection vulnerability Source: CONFIRM Type: Patch, Vendor Advisory http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-1 Source: BID Type: Patch 28068 Source: CCN Type: BID-28068 phpMyAdmin '$_REQUEST' SQL Injection Vulnerability Source: VUPEN Type: Vendor Advisory ADV-2008-0731 Source: VUPEN Type: Vendor Advisory ADV-2008-0758 Source: XF Type: UNKNOWN phpmyadmin-request-sql-injection(40968) Source: XF Type: UNKNOWN phpmyadmin-request-sql-injection(40968) Source: FEDORA Type: UNKNOWN FEDORA-2008-2189 Source: FEDORA Type: UNKNOWN FEDORA-2008-2229 Source: SUSE Type: SUSE-SR:2008:026 SUSE Security Summary Report Source: SUSE Type: SUSE-SR:2009:003 SUSE Security Summary Report | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |