Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-1924
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-1924

Description:
Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variable.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/41964

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html
  http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html

SAID
  Secunia Advisory: SA30034
  Secunia Advisory: SA29964
  Secunia Advisory: SA29944
  Secunia Advisory: SA30816
  Secunia Advisory: SA32834
  Secunia Advisory: SA33822

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:131

GENTOO
  http://security.gentoo.org/glsa/glsa-200805-02.xml

DEBIAN
  http://www.debian.org/security/2008/dsa-1557

CONFIRM
  http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-3

BID
  28906


Return to the previous page.