CVE-2006-5116
EPSS 2.1%
描述
Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdmin before 2.9.1-rc1 allow remote attackers to perform unauthorized actions as another user by (1) directly setting a token in the URL though dynamic variable evaluation and (2) unsetting arbitrary variables via the _REQUEST array, related to (a) libraries/common.lib.php, (b) session.inc.php, and (c) url_generating.lib.php. NOTE: the PHP unset function vector is covered by CVE-2006-3017.
如何修補 CVE-2006-5116
要修補 CVE-2006-5116,請將受影響套件升級到下列已修補版本。
- Debian/phpmyadmin—升級至 4:2.9.0.2-0.1 或更新版本
CVE-2006-5116 正在被利用嗎?
低 — EPSS 為 2.1%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 4:2.9.0.2-0.1