National Cyber Awareness System
Vulnerability Summary for CVE-2008-1924
Original release date:04/23/2008
Last revised:04/12/2011
Source:
US-CERT/NIST
Overview
Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variable.
Impact
CVSS Severity (version 2.0):
Impact Subscore:
2.9
Exploitability Subscore:
6.8
CVSS Version 2 Metrics:
Access Vector: Network exploitable
Access Complexity: Medium
Authentication: Required to exploit
Impact Type:Allows unauthorized disclosure of information
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.
External Source: BID
Name: 28906
Type: Patch Information
External Source: XF
Name: phpmyadmin-unspecified-info-disclosure(41964)
External Source: VUPEN
Name: ADV-2008-1328
Type: Advisory
External Source: CONFIRM
Name: http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-3
Type: Advisory
External Source: MANDRIVA
Name: MDVSA-2008:131
External Source: DEBIAN
Name: DSA-1557
External Source: GENTOO
Name: GLSA-200805-02
External Source: SECUNIA
Name: 33822
Type: Advisory
External Source: SECUNIA
Name: 32834
Type: Advisory
External Source: SECUNIA
Name: 30816
Type: Advisory
External Source: SECUNIA
Name: 30034
Type: Advisory
External Source: SECUNIA
Name: 29964
Type: Advisory
External Source: SECUNIA
Name: 29944
Type: Advisory
External Source: SUSE
Name: SUSE-SR:2009:003
External Source: SUSE
Name: SUSE-SR:2008:026