7.5
CWE
NVD-CWE-Other 89 352
Advisory Published
CVE Published
Updated

CVE-2005-4450: SQL Injection

First published: Wed Dec 21 2005(Updated: )

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
phpMyAdmin=2.7.0_pl1

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What are the potential impacts of CVE-2005-4450?

    CVE-2005-4450 allows remote attackers to perform unauthorized actions as a logged-in user due to CSRF vulnerabilities in phpMyAdmin.

  • Who is affected by CVE-2005-4450?

    CVE-2005-4450 affects users of phpMyAdmin version 2.7.0 and specifically those using the server_privileges.php functionality.

  • How can I mitigate CVE-2005-4450?

    To mitigate CVE-2005-4450, update phpMyAdmin to a version that is not vulnerable to this CSRF attack.

  • Is CVE-2005-4450 a critical vulnerability?

    CVE-2005-4450 is considered serious since it allows unauthorized actions to be taken on behalf of legitimate users.

  • What should I do if I suspect exploitation of CVE-2005-4450?

    If you suspect exploitation of CVE-2005-4450, immediately assess your system, change affected passwords, and apply necessary updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203