PMASA-2008-5
Announcement-ID: PMASA-2008-5
Date: 2008-07-15
Updated: 2008-07-16
Summary
XSRF/CSRF for creating a database and modifying user charset
Description
We received an advisory from Aung Khant (YGN Ethical Hacker Group), and we wish to thank him for his work. A logged-in user, if abused into clicking a crafted link or loading an attack page, would create a database he did not intend to, or would change his connection character set.
Severity
We consider this vulnerability to be serious.
Affected Versions
Versions before 2.11.7.1.
Solution
Upgrade to phpMyAdmin 2.11.7.1 or newer.
References
These advisories are available from the reporter:
http://yehg.net/lab/pr0js/advisories/XSRF_CreateDB_inPhpMyAdmin2.11.7.pdf
http://yehg.net/lab/pr0js/advisories/XSRF_ConvertCharset_inPhpMyAdmin2.11.7.pdf
Assigned CVE IDs: CVE-2008-3197
Patches
The following commits have been made to fix this issue:
More information
For further information and in case of questions, please contact the phpMyAdmin security team at security@phpmyadmin.net.