6.4
CVSSv2

CVE-2008-3456

Published: 04/08/2008 Updated: 08/08/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

phpMyAdmin prior to 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote malicious users to conduct spoofing or phishing activities via a cross-site framing attack.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.0.4

phpmyadmin phpmyadmin 2.0.5

phpmyadmin phpmyadmin 2.1

phpmyadmin phpmyadmin 2.10.0.2

phpmyadmin phpmyadmin 2.10.01

phpmyadmin phpmyadmin 2.11.0

phpmyadmin phpmyadmin 2.11.0.0

phpmyadmin phpmyadmin 2.11.2.2

phpmyadmin phpmyadmin 2.11.3

phpmyadmin phpmyadmin 2.11.5.2

phpmyadmin phpmyadmin 2.11.6

phpmyadmin phpmyadmin 2.0.0

phpmyadmin phpmyadmin 2.0.2

phpmyadmin phpmyadmin 2.0.3

phpmyadmin phpmyadmin 2.10.0.0

phpmyadmin phpmyadmin 2.10.0.1

phpmyadmin phpmyadmin 2.10.3

phpmyadmin phpmyadmin 2.10.3.0

phpmyadmin phpmyadmin 2.11.2

phpmyadmin phpmyadmin 2.11.2.0

phpmyadmin phpmyadmin 2.11.2.1

phpmyadmin phpmyadmin 2.11.5.0

phpmyadmin phpmyadmin 2.11.5.1

phpmyadmin phpmyadmin 2.0.1

phpmyadmin phpmyadmin 2.1.2

phpmyadmin phpmyadmin 2.10.0

phpmyadmin phpmyadmin 2.10.2

phpmyadmin phpmyadmin 2.10.2.0

phpmyadmin phpmyadmin 2.11.1.1

phpmyadmin phpmyadmin 2.11.1.2

phpmyadmin phpmyadmin 2.11.4.0

phpmyadmin phpmyadmin 2.11.5

phpmyadmin phpmyadmin 2.0

phpmyadmin phpmyadmin 2.1.0

phpmyadmin phpmyadmin 2.1.1

phpmyadmin phpmyadmin 2.10.1

phpmyadmin phpmyadmin 2.10.1.0

phpmyadmin phpmyadmin 2.11.1

phpmyadmin phpmyadmin 2.11.1.0

phpmyadmin phpmyadmin 2.11.3.0

phpmyadmin phpmyadmin 2.11.4

phpmyadmin phpmyadmin

Vendor Advisories

Several remote vulnerabilities have been discovered in phpMyAdmin, a tool to administrate MySQL databases over the web The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-4096 Remote authenticated users could execute arbitrary code on the host running phpMyAdmin through manipulation of a script par ...