CVE-2008-1149
published 2008-03-04CVE-2008-1149: phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override…
PriorityP421medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
0.91%
56.0th percentile
phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:2.11.5-1 (bookworm) | phpmyadmin 4:2.11.5-1 (bookworm) |
| phpmyadmin | phpmyadmin | <= 2.11.4 | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 4:2.11.5-1 | 4:2.11.5-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:2.11.5-1 | 4:2.11.5-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:2.11.5-1 | 4:2.11.5-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:2.11.5-1 | 4:2.11.5-1 |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1LOW
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
phpMyAdmin 2.11.5 contains a security fix
vendor_redhat·2008-03-01·CVSS 5.1
CVE-2008-1149 [MEDIUM] phpMyAdmin 2.11.5 contains a security fix
phpMyAdmin 2.11.5 contains a security fix
phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.
Debian
CVE-2008-1149: phpmyadmin - phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of...
vendor_debian·2008·CVSS 5.1
CVE-2008-1149 [MEDIUM] CVE-2008-1149: phpmyadmin - phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of...
phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.
Scope: local
bookworm: resolved (fixed in 4:2.11.5-1)
bullseye: resolved (fixed in 4:2.11.5-1)
forky: resolved (fixed in 4:2.11.5-1)
sid: resolved (fixed in 4:2.11.5-1)
trixie: resolved (fixed in 4:2.11.5-1)
GHSA
GHSA-p842-vv7g-4q9v: phpMyAdmin before 2
ghsa_unreviewed·2022-05-01
CVE-2008-1149 [MEDIUM] CWE-352 GHSA-p842-vv7g-4q9v: phpMyAdmin before 2
phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.
OSV
CVE-2008-1149: phpMyAdmin before 2
osv·2008-03-04·CVSS 5.1
CVE-2008-1149 [MEDIUM] CVE-2008-1149: phpMyAdmin before 2
phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.htmlhttp://secunia.com/advisories/29143http://secunia.com/advisories/29200http://secunia.com/advisories/29287http://secunia.com/advisories/29964http://secunia.com/advisories/30816http://secunia.com/advisories/32834http://secunia.com/advisories/33822http://www.debian.org/security/2008/dsa-1557http://www.gentoo.org/security/en/glsa/glsa-200803-15.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:131http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-1http://www.securityfocus.com/bid/28068http://www.vupen.com/english/advisories/2008/0731http://www.vupen.com/english/advisories/2008/0758https://exchange.xforce.ibmcloud.com/vulnerabilities/40968https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00069.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-March/msg00100.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.htmlhttp://secunia.com/advisories/29143http://secunia.com/advisories/29200http://secunia.com/advisories/29287http://secunia.com/advisories/29964http://secunia.com/advisories/30816http://secunia.com/advisories/32834http://secunia.com/advisories/33822http://www.debian.org/security/2008/dsa-1557http://www.gentoo.org/security/en/glsa/glsa-200803-15.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:131http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-1http://www.securityfocus.com/bid/28068http://www.vupen.com/english/advisories/2008/0731http://www.vupen.com/english/advisories/2008/0758https://exchange.xforce.ibmcloud.com/vulnerabilities/40968https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00069.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-March/msg00100.html
2008-03-04
Published