CVE-2008-5621: CSRF
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tblstructure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5621?
CVE-2008-5621 is categorized as a medium severity vulnerability affecting certain versions of phpMyAdmin due to its potential for a cross-site request forgery (CSRF) attack.
How do I fix CVE-2008-5621?
To mitigate CVE-2008-5621, it is recommended to upgrade to phpMyAdmin version 2.11.9.4 or later, or 3.1.1.0 or later.
Which versions of phpMyAdmin are affected by CVE-2008-5621?
CVE-2008-5621 affects phpMyAdmin versions 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0.
What type of attack can exploit CVE-2008-5621?
CVE-2008-5621 can be exploited through a cross-site request forgery (CSRF) attack that allows unauthorized actions as the administrator.
Who is affected by CVE-2008-5621?
Users and administrators running vulnerable versions of phpMyAdmin are affected by CVE-2008-5621.