peter bassill · operator
$ cve CVE-2008-5621 JSON

CVE-2008-5621 EXPLOIT

6.0
MEDIUM · CVSS 2.0 · EPSS 2.2% (pctl 82)

Patch early

A public exploit exists.

Description

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

Scoring

CVSS6.0 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS2.15% — more likely to be exploited than 82% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2008-12-17
Last modified2026-06-16

Affected (1)

VendorProduct
phpmyadminphpmyadmin

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD