CVE-2008-1567
published 2008-03-31CVE-2008-1567: phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which…
PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.30%
21.5th percentile
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | phpmyadmin | < phpmyadmin 2.11.5.1 (bookworm) | phpmyadmin 2.11.5.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| phpmyadmin | phpmyadmin | < 2.11.5.1 | 2.11.5.1 |
| phpmyadmin | phpmyadmin | >= 0 < 2.11.5.1 | 2.11.5.1 |
| phpmyadmin | phpmyadmin | >= 0 < 2.11.5.1 | 2.11.5.1 |
| phpmyadmin | phpmyadmin | >= 0 < 2.11.5.1 | 2.11.5.1 |
| phpmyadmin | phpmyadmin | >= 0 < 2.11.5.1 | 2.11.5.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-43mv-f787-vp98: phpMyAdmin before 2
ghsa_unreviewed·2022-05-01
CVE-2008-1567 [LOW] CWE-200 GHSA-43mv-f787-vp98: phpMyAdmin before 2
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
OSV
CVE-2008-1567: phpMyAdmin before 2
osv·2008-03-31·CVSS 5.5
CVE-2008-1567 [MEDIUM] CVE-2008-1567: phpMyAdmin before 2
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
Debian
CVE-2008-1567: phpmyadmin - phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and t...
vendor_debian·2008·CVSS 5.5
CVE-2008-1567 [MEDIUM] CVE-2008-1567: phpmyadmin - phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and t...
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
Scope: local
bookworm: resolved (fixed in 2.11.5.1)
bullseye: resolved (fixed in 2.11.5.1)
forky: resolved (fixed in 2.11.5.1)
sid: resolved (fixed in 2.11.5.1)
trixie: resolved (fixed in 2.11.5.1)
Red Hat
phpMyAdmin: user/password/secret key are stored plaintext
vendor_redhat·CVSS 5.5
CVE-2008-1567 [MEDIUM] phpMyAdmin: user/password/secret key are stored plaintext
phpMyAdmin: user/password/secret key are stored plaintext
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
No detection rules found.
No public exploits indexed.
CWE
Missing Encryption of Sensitive Data
mitre_cwe
CWE-311 Missing Encryption of Sensitive Data
CWE-311: Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
Modes of Introduction:
Phase: Architecture and Design
Note: OMISSION: This weakness is caused by missing a security tactic during the architecture and design phase.
Phase: Operation
Common Consequences:
Scope: Confidentiality. Impact: Read Application Data. If the application does not use a secure channel, such as SSL, to exchange sensitive information, it is possible for an attacker with access to the network traffic to sniff packets from the connection and uncover the data. This attack is not technically difficult, but does require physical access to some portion of the network over which the sensitive data travels. This access is usually somewhe
CWE
Cleartext Storage of Sensitive Information
mitre_cwe
CWE-312 Cleartext Storage of Sensitive Information
CWE-312: Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Modes of Introduction:
Phase: Architecture and Design
Note: OMISSION: This weakness is caused by missing a security tactic during the architecture and design phase.
Common Consequences:
Scope: Confidentiality. Impact: Read Application Data. An attacker with access to the system could read sensitive information stored in cleartext (i.e., unencrypted). Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.
Detection Methods:
Automated Static Analysis: Automated static analysis, commonly referred to as Stat
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.htmlhttp://secunia.com/advisories/29588http://secunia.com/advisories/29613http://secunia.com/advisories/29964http://secunia.com/advisories/30816http://secunia.com/advisories/32834http://secunia.com/advisories/33822http://sourceforge.net/tracker/index.php?func=detail&aid=1909711&group_id=23067&atid=377408http://www.debian.org/security/2008/dsa-1557http://www.mandriva.com/security/advisories?name=MDVSA-2008:131http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-2http://www.securityfocus.com/bid/28560http://www.vupen.com/english/advisories/2008/1037/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41541https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00031.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00080.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.htmlhttp://secunia.com/advisories/29588http://secunia.com/advisories/29613http://secunia.com/advisories/29964http://secunia.com/advisories/30816http://secunia.com/advisories/32834http://secunia.com/advisories/33822http://sourceforge.net/tracker/index.php?func=detail&aid=1909711&group_id=23067&atid=377408http://www.debian.org/security/2008/dsa-1557http://www.mandriva.com/security/advisories?name=MDVSA-2008:131http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-2http://www.securityfocus.com/bid/28560http://www.vupen.com/english/advisories/2008/1037/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41541https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00031.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00080.html
2008-03-31
Published