First published: Tue Jan 19 2010(Updated: )
`libraries/File.class.php` in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vectors.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/phpmyadmin/phpmyadmin | >=2.11.0<2.11.10 | 2.11.10 |
PhpMyAdmin | =2.11.0 | |
PhpMyAdmin | =2.11.0-beta1 | |
PhpMyAdmin | =2.11.0-rc1 | |
PhpMyAdmin | =2.11.0.0 | |
PhpMyAdmin | =2.11.0beta1 | |
PhpMyAdmin | =2.11.0rc1 | |
PhpMyAdmin | =2.11.1 | |
PhpMyAdmin | =2.11.1-rc1 | |
PhpMyAdmin | =2.11.1.0 | |
PhpMyAdmin | =2.11.1.1 | |
PhpMyAdmin | =2.11.1.2 | |
PhpMyAdmin | =2.11.1rc1 | |
PhpMyAdmin | =2.11.2 | |
PhpMyAdmin | =2.11.2.0 | |
PhpMyAdmin | =2.11.2.1 | |
PhpMyAdmin | =2.11.2.2 | |
PhpMyAdmin | =2.11.3 | |
PhpMyAdmin | =2.11.3-rc1 | |
PhpMyAdmin | =2.11.3.0 | |
PhpMyAdmin | =2.11.3rc1 | |
PhpMyAdmin | =2.11.4 | |
PhpMyAdmin | =2.11.4-rc1 | |
PhpMyAdmin | =2.11.4.0 | |
PhpMyAdmin | =2.11.4rc1 | |
PhpMyAdmin | =2.11.5 | |
PhpMyAdmin | =2.11.5-rc1 | |
PhpMyAdmin | =2.11.5.0 | |
PhpMyAdmin | =2.11.5.1 | |
PhpMyAdmin | =2.11.5.2 | |
PhpMyAdmin | =2.11.5rc1 | |
PhpMyAdmin | =2.11.6 | |
PhpMyAdmin | =2.11.6-rc1 | |
PhpMyAdmin | =2.11.6.0 | |
PhpMyAdmin | =2.11.6rc1 | |
PhpMyAdmin | =2.11.7 | |
PhpMyAdmin | =2.11.7.0 | |
PhpMyAdmin | =2.11.8 | |
PhpMyAdmin | =2.11.9 | |
PhpMyAdmin | =2.11.9.0 | |
PhpMyAdmin | =2.11.9.1 | |
PhpMyAdmin | =2.11.9.2 | |
PhpMyAdmin | =2.11.9.3 | |
PhpMyAdmin | =2.11.9.4 | |
PhpMyAdmin | =2.11.9.5 | |
PhpMyAdmin | =2.11.9.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-7252 has an unknown impact and attack vectors due to predictable filenames for temporary files in phpMyAdmin.
To fix CVE-2008-7252, upgrade phpMyAdmin to version 2.11.10 or later.
CVE-2008-7252 affects phpMyAdmin versions 2.11.x before 2.11.10.
The vulnerability is related to the libraries/File.class.php file in phpMyAdmin.
There is no known workaround for CVE-2008-7252, and upgrading is the recommended mitigation.