5.1
CVSSv2

CVE-2006-5116

Published: 03/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdmin prior to 2.9.1-rc1 allow remote malicious users to perform unauthorized actions as another user by (1) directly setting a token in the URL though dynamic variable evaluation and (2) unsetting arbitrary variables via the _REQUEST array, related to (a) libraries/common.lib.php, (b) session.inc.php, and (c) url_generating.lib.php. NOTE: the PHP unset function vector is covered by CVE-2006-3017.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.8.1 dev

phpmyadmin phpmyadmin 2.8.3

phpmyadmin phpmyadmin 2.8.0.2

phpmyadmin phpmyadmin 2.9.0 dev

phpmyadmin phpmyadmin 2.8.0.1

phpmyadmin phpmyadmin 2.8.1

phpmyadmin phpmyadmin 2.8.0.3

phpmyadmin phpmyadmin 2.8.4

Vendor Advisories

Debian Bug report logs - #391090 phpmyadmin: security issue PMASA-2006-5 Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Laurent Bonnaud <LaurentBonnaud@inpgfr> Date: Wed, 4 Oct 2006 20:33:02 UTC Sever ...
Debian Bug report logs - #377748 phpmyadmin: CVE-2006-3388: cross-site scripting Package: phpmyadmin; Maintainer for phpmyadmin is Thijs Kinkhorst <thijs@debianorg>; Source for phpmyadmin is src:phpmyadmin (PTS, buildd, popcon) Reported by: Alec Berryman <alec@thenednet> Date: Tue, 11 Jul 2006 01:33:05 UTC Severit ...
The phpmyadmin update in DSA 1207 introduced a regression This update corrects this flaw For completeness, please find below the original advisory text: Several remote vulnerabilities have been discovered in phpMyAdmin, a program to administrate MySQL over the web The Common Vulnerabilities and Exposures project identifies the following problem ...