Severity
5.5MEDIUMNVD
EPSS
0.0%
top 87.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateMay 1

Description

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

debiandebian/phpmyadmin< phpmyadmin 2.11.5.1 (bookworm)
NVDphpmyadmin/phpmyadmin< 2.11.5.1
Debianphpmyadmin/phpmyadmin< 2.11.5.1+3
NVDopensuse/opensuse10.2, 10.3, 11.0+2

Also affects: Debian Linux 4.0, Fedora 7, 8

Patches

🔴Vulnerability Details

2
GHSA
GHSA-43mv-f787-vp98: phpMyAdmin before 22022-05-01
OSV
CVE-2008-1567: phpMyAdmin before 22008-03-31

📋Vendor Advisories

2
Debian
CVE-2008-1567: phpmyadmin - phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and t...2008
Red Hat
phpMyAdmin: user/password/secret key are stored plaintext

📐Framework References

2
CWE
Missing Encryption of Sensitive Data
CWE
Cleartext Storage of Sensitive Information

💬Community

1
Bugzilla
CVE-2008-1567 phpMyAdmin: user/password/secret key are stored plaintext2008-04-01