CVE-2008-1149

EPSS 0.93%

phpmyadmin - several vulnerabilities

發布日:2008/3/4修改日:2026/3/9
也稱為:DSA-1557-1DEBIAN-CVE-2008-1149

描述

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

受影響套件(2)

參考連結(1)