PMASA-2006-5
Announcement-ID: PMASA-2006-5
Date: 2006-10-01
Summary
XSRF (Cross Site Request Forgery) vulnerabilities
Description
We received a security advisory from Stefan Esser (sesser@hardened-php.net) and we wish to thank him for his work. It was possible to inject arbitrary SQL commands by forcing an authenticated user to follow a crafted link.
Severity
We consider these vulnerabilities to be serious.
Affected Versions
At least versions since 2.8.2.x.
Solution
Upgrade to phpMyAdmin 2.9.0.1 or newer.
References
Assigned CVE IDs: CVE-2006-5116
Patches
The following commits have been made to fix this issue:
- b3906852bbcb5c4e116cc20e214b7f6793ca97aa
- ac2f606a21d474596a4b2cada961385439cbc8f0
- 50319d634c620044a0542495939cd68530f00259
More information
For further information and in case of questions, please contact the phpMyAdmin security team at security@phpmyadmin.net.