CVE Vulnerabilities

CVE-2009-4605

Published: Jan 19, 2010 | Modified: May 06, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Phpmyadmin Phpmyadmin 2.11.0 (including) 2.11.0 (including)
Phpmyadmin Phpmyadmin 2.11.1.0 (including) 2.11.1.0 (including)
Phpmyadmin Phpmyadmin 2.11.1.1 (including) 2.11.1.1 (including)
Phpmyadmin Phpmyadmin 2.11.1.2 (including) 2.11.1.2 (including)
Phpmyadmin Phpmyadmin 2.11.2.0 (including) 2.11.2.0 (including)
Phpmyadmin Phpmyadmin 2.11.2.1 (including) 2.11.2.1 (including)
Phpmyadmin Phpmyadmin 2.11.2.2 (including) 2.11.2.2 (including)
Phpmyadmin Phpmyadmin 2.11.3.0 (including) 2.11.3.0 (including)
Phpmyadmin Phpmyadmin 2.11.4.0 (including) 2.11.4.0 (including)
Phpmyadmin Phpmyadmin 2.11.5.0 (including) 2.11.5.0 (including)
Phpmyadmin Phpmyadmin 2.11.5.1 (including) 2.11.5.1 (including)
Phpmyadmin Phpmyadmin 2.11.5.2 (including) 2.11.5.2 (including)
Phpmyadmin Phpmyadmin 2.11.6.0 (including) 2.11.6.0 (including)
Phpmyadmin Phpmyadmin 2.11.7.0 (including) 2.11.7.0 (including)
Phpmyadmin Phpmyadmin 2.11.7.1 (including) 2.11.7.1 (including)
Phpmyadmin Phpmyadmin 2.11.8.0 (including) 2.11.8.0 (including)
Phpmyadmin Phpmyadmin 2.11.9.0 (including) 2.11.9.0 (including)
Phpmyadmin Phpmyadmin 2.11.9.1 (including) 2.11.9.1 (including)
Phpmyadmin Phpmyadmin 2.11.9.2 (including) 2.11.9.2 (including)
Phpmyadmin Phpmyadmin 2.11.9.3 (including) 2.11.9.3 (including)
Phpmyadmin Phpmyadmin 2.11.9.4 (including) 2.11.9.4 (including)
Phpmyadmin Phpmyadmin 2.11.9.5 (including) 2.11.9.5 (including)
Phpmyadmin Phpmyadmin 2.11.9.6 (including) 2.11.9.6 (including)

References