5.5
CVSSv3

CVE-2008-1567

Published: 31/03/2008 Updated: 14/02/2024
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

phpMyAdmin prior to 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin

debian debian linux 4.0

fedoraproject fedora 8

fedoraproject fedora 7

opensuse opensuse 10.2

opensuse opensuse 11.0

opensuse opensuse 10.3