CVE-2008-1149

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
phpmyadminphpmyadmin
𝑥
≤ 2.11.4
phpmyadminphpmyadmin
2.11.0
phpmyadminphpmyadmin
2.11.0:beta1
phpmyadminphpmyadmin
2.11.0:rc1
phpmyadminphpmyadmin
2.11.0.0
phpmyadminphpmyadmin
2.11.1
phpmyadminphpmyadmin
2.11.1:rc1
phpmyadminphpmyadmin
2.11.1.0
phpmyadminphpmyadmin
2.11.1.1
phpmyadminphpmyadmin
2.11.1.2
phpmyadminphpmyadmin
2.11.2
phpmyadminphpmyadmin
2.11.2.0
phpmyadminphpmyadmin
2.11.2.1
phpmyadminphpmyadmin
2.11.2.2
phpmyadminphpmyadmin
2.11.3
phpmyadminphpmyadmin
2.11.3:rc1
phpmyadminphpmyadmin
2.11.3.0
phpmyadminphpmyadmin
2.11.4:rc1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
phpmyadmin
bullseye
4:5.0.4+dfsg2-2+deb11u1
fixed
etch
no-dsa
sarge
not-affected
bookworm
4:5.2.1+dfsg-1
fixed
sid
4:5.2.1+dfsg-4
fixed
trixie
4:5.2.1+dfsg-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
phpmyadmin
gutsy
Fixed 4:2.10.3-1ubuntu0.2
released
feisty
Fixed 4:2.9.1.1-2ubuntu1.2
released
edgy
Fixed 4:2.8.2-0.2ubuntu0.1
released
dapper
Fixed 4:2.8.0.3-1ubuntu0.1
released
References