First published: Thu Nov 15 2007(Updated: )
SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | <=2.11.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5976 has a severity rating that indicates it allows for SQL injection attacks, which can lead to unauthorized database access.
To fix CVE-2007-5976, upgrade phpMyAdmin to the latest version, specifically 2.11.2.1 or newer.
CVE-2007-5976 affects phpMyAdmin versions prior to 2.11.2.1.
Remote authenticated users with CREATE DATABASE privileges are at risk from CVE-2007-5976.
CVE-2007-5976 can lead to execution of arbitrary SQL commands on the affected database.