CVE-2008-1149

Publication date 4 March 2008

Last updated 24 July 2024


Ubuntu priority

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

Status

Package Ubuntu Release Status
phpmyadmin 7.10 gutsy
Fixed 4:2.10.3-1ubuntu0.2
7.04 feisty
Fixed 4:2.9.1.1-2ubuntu1.2
6.10 edgy
Fixed 4:2.8.2-0.2ubuntu0.1
6.06 LTS dapper
Fixed 4:2.8.0.3-1ubuntu0.1