Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2008-1149

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

  • Published: Mar 5, 2008
  • Updated: Apr 13, 2023
  • CVE: CVE-2008-1149
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5.1
  • AV:N/AC:H/Au:N/C:P/I:P/A:P
Software From Fixed in
phpmyadmin / phpmyadmin 2.11.1.2 2.11.1.2.x
phpmyadmin / phpmyadmin 2.11.1 2.11.1.x
phpmyadmin / phpmyadmin - 2.11.4.x
phpmyadmin / phpmyadmin 2.11.0-beta1 2.11.0-beta1.x
phpmyadmin / phpmyadmin 2.11.2 2.11.2.x
phpmyadmin / phpmyadmin 2.11.2.2 2.11.2.2.x
phpmyadmin / phpmyadmin 2.11.1-rc1 2.11.1-rc1.x
phpmyadmin / phpmyadmin 2.11.3 2.11.3.x
phpmyadmin / phpmyadmin 2.11.2.1 2.11.2.1.x
phpmyadmin / phpmyadmin 2.11.3-rc1 2.11.3-rc1.x
phpmyadmin / phpmyadmin 2.11.0-rc1 2.11.0-rc1.x
phpmyadmin / phpmyadmin 2.11.2.0 2.11.2.0.x
phpmyadmin / phpmyadmin 2.11.4-rc1 2.11.4-rc1.x
phpmyadmin / phpmyadmin 2.11.1.1 2.11.1.1.x
phpmyadmin / phpmyadmin 2.11.3.0 2.11.3.0.x
phpmyadmin / phpmyadmin 2.11.0.0 2.11.0.0.x
phpmyadmin / phpmyadmin 2.11.1.0 2.11.1.0.x
phpmyadmin / phpmyadmin 2.11.0 2.11.0.x