Total vulnerabilities in the database
phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.
Software | From | Fixed in |
---|---|---|
phpmyadmin / phpmyadmin | 2.11.1.2 | 2.11.1.2.x |
phpmyadmin / phpmyadmin | 2.11.1 | 2.11.1.x |
phpmyadmin / phpmyadmin | - | 2.11.4.x |
phpmyadmin / phpmyadmin | 2.11.0-beta1 | 2.11.0-beta1.x |
phpmyadmin / phpmyadmin | 2.11.2 | 2.11.2.x |
phpmyadmin / phpmyadmin | 2.11.2.2 | 2.11.2.2.x |
phpmyadmin / phpmyadmin | 2.11.1-rc1 | 2.11.1-rc1.x |
phpmyadmin / phpmyadmin | 2.11.3 | 2.11.3.x |
phpmyadmin / phpmyadmin | 2.11.2.1 | 2.11.2.1.x |
phpmyadmin / phpmyadmin | 2.11.3-rc1 | 2.11.3-rc1.x |
phpmyadmin / phpmyadmin | 2.11.0-rc1 | 2.11.0-rc1.x |
phpmyadmin / phpmyadmin | 2.11.2.0 | 2.11.2.0.x |
phpmyadmin / phpmyadmin | 2.11.4-rc1 | 2.11.4-rc1.x |
phpmyadmin / phpmyadmin | 2.11.1.1 | 2.11.1.1.x |
phpmyadmin / phpmyadmin | 2.11.3.0 | 2.11.3.0.x |
phpmyadmin / phpmyadmin | 2.11.0.0 | 2.11.0.0.x |
phpmyadmin / phpmyadmin | 2.11.1.0 | 2.11.1.0.x |
phpmyadmin / phpmyadmin | 2.11.0 | 2.11.0.x |