Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2008-5621 at MITRE


Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before and 3.x before allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.
CVSS v2 Scores
  National Vulnerability Database
Base Score 6.00
Vector AV:N/AC:M/Au:S/C:P/I:P/A:P
Access Vector Network
Access Complexity Medium
Authentication Single
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial

SUSE information

SUSE Bugzilla entry: 457889 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 11.0
  • phpMyAdmin >=