CVE-2008-5621

Publication date 17 December 2008

Last updated 24 July 2024


Ubuntu priority

Description

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

Status

Package Ubuntu Release Status
phpmyadmin 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Fixed 4:2.11.8.1-1ubuntu0.1
8.04 LTS hardy
Fixed 4:2.11.3-1ubuntu1.2
7.10 gutsy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
phpmyadmin