3.5
CVSSv2

CVE-2008-1924

Published: 23/04/2008 Updated: 08/08/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

Unspecified vulnerability in phpMyAdmin prior to 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variable.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.10.0.2

phpmyadmin phpmyadmin 2.10.1

phpmyadmin phpmyadmin 2.11.1.1

phpmyadmin phpmyadmin 2.11.1.2

phpmyadmin phpmyadmin 2.11.4

phpmyadmin phpmyadmin 2.11.4rc1

phpmyadmin phpmyadmin 2.10.0

phpmyadmin phpmyadmin 2.10.0.1

phpmyadmin phpmyadmin 2.11.0beta1

phpmyadmin phpmyadmin 2.11.0rc1

phpmyadmin phpmyadmin 2.11.1

phpmyadmin phpmyadmin 2.11.3

phpmyadmin phpmyadmin 2.11.3rc1

phpmyadmin phpmyadmin 2.10.2

phpmyadmin phpmyadmin 2.10.3

phpmyadmin phpmyadmin 2.11.1rc1

phpmyadmin phpmyadmin 2.11.2

phpmyadmin phpmyadmin 2.11.5

phpmyadmin phpmyadmin 2.11.6rc1

phpmyadmin phpmyadmin 2.10.3rc1

phpmyadmin phpmyadmin 2.11.0

phpmyadmin phpmyadmin 2.11.2.1

phpmyadmin phpmyadmin 2.11.2.2

phpmyadmin phpmyadmin