CVE-2005-4450: SQL Injection
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to serverprivileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed.
Affected Software
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2005-4450?
CVE-2005-4450 allows remote attackers to perform unauthorized actions as a logged-in user due to CSRF vulnerabilities in phpMyAdmin.
Who is affected by CVE-2005-4450?
CVE-2005-4450 affects users of phpMyAdmin version 2.7.0 and specifically those using the server_privileges.php functionality.
How can I mitigate CVE-2005-4450?
To mitigate CVE-2005-4450, update phpMyAdmin to a version that is not vulnerable to this CSRF attack.
Is CVE-2005-4450 a critical vulnerability?
CVE-2005-4450 is considered serious since it allows unauthorized actions to be taken on behalf of legitimate users.
What should I do if I suspect exploitation of CVE-2005-4450?
If you suspect exploitation of CVE-2005-4450, immediately assess your system, change affected passwords, and apply necessary updates.