CVE-2008-1149

EPSS 0.93%

phpmyadmin - several vulnerabilities

Published: 3/4/2008Modified: 3/9/2026
Also known as:DSA-1557-1DEBIAN-CVE-2008-1149

Description

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

Affected packages (2)

References (1)