First published: Wed Dec 21 2005(Updated: )
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin | =2.7.0_pl1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4450 allows remote attackers to perform unauthorized actions as a logged-in user due to CSRF vulnerabilities in phpMyAdmin.
CVE-2005-4450 affects users of phpMyAdmin version 2.7.0 and specifically those using the server_privileges.php functionality.
To mitigate CVE-2005-4450, update phpMyAdmin to a version that is not vulnerable to this CSRF attack.
CVE-2005-4450 is considered serious since it allows unauthorized actions to be taken on behalf of legitimate users.
If you suspect exploitation of CVE-2005-4450, immediately assess your system, change affected passwords, and apply necessary updates.