5.1
CVSSv2

CVE-2006-5116

Published: 03/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdmin prior to 2.9.1-rc1 allow remote malicious users to perform unauthorized actions as another user by (1) directly setting a token in the URL though dynamic variable evaluation and (2) unsetting arbitrary variables via the _REQUEST array, related to (a) libraries/common.lib.php, (b) session.inc.php, and (c) url_generating.lib.php. NOTE: the PHP unset function vector is covered by CVE-2006-3017.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.8.0.1

phpmyadmin phpmyadmin 2.9.0_dev

phpmyadmin phpmyadmin 2.8.0.2

phpmyadmin phpmyadmin 2.8.0.3

phpmyadmin phpmyadmin 2.8.1

phpmyadmin phpmyadmin 2.8.1_dev

phpmyadmin phpmyadmin 2.8.3

phpmyadmin phpmyadmin 2.8.4

Vendor Advisories

Debian Bug report logs - #391090 phpmyadmin: security issue PMASA-2006-5 Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Laurent Bonnaud <LaurentBonnaud@inpgfr> Date: Wed, 4 Oct 2006 20:33:02 UTC Sever ...
Debian Bug report logs - #377748 phpmyadmin: CVE-2006-3388: cross-site scripting Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Alec Berryman <alec@thenednet> Date: Tue, 11 Jul 2006 01:33:05 UTC Severit ...
The phpmyadmin update in DSA 1207 introduced a regression This update corrects this flaw For completeness, please find below the original advisory text: Several remote vulnerabilities have been discovered in phpMyAdmin, a program to administrate MySQL over the web The Common Vulnerabilities and Exposures project identifies the following problem ...