FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-5621

This CVE name corresponds to:

Entered Topic
2008-12-11 phpmyadmin -- cross-site request forgery vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-5621
Phase Assigned(20081216)

Description

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

References

Source Reference
MILW0RM 7382
MLIST [oss-security] 20090212 CVE-2008-5621 is a duplicate (was: Re: CVE request: phpMyAdmin < 3.1.1.0 (SQL injection through XSRF on several pages ))
CONFIRM http://www.phpmyadmin.net/home_page/security/PMASA-2008-10.php
CONFIRM http://typo3.org/teams/security/security-bulletins/typo3-20081222-1/
DEBIAN DSA-1723
FEDORA FEDORA-2008-11221
FEDORA FEDORA-2008-11221
GENTOO GLSA-200903-32
SUSE SUSE-SR:2009:003
BID 32720
OSVDB 50894
SECUNIA 33246
VUPEN ADV-2008-3402
SECUNIA 33076
SECUNIA 33146
SECUNIA 33912
SECUNIA 33822
SREASON 4753
VUPEN ADV-2008-3501
XF phpmyadmin-tblstructure-csrf(47168)