CVE-2008-1567 (phpMyAdmin) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2008-1567 (phpMyAdmin)


Heap
01-04-08, 16:23
phpMyAdmin before 2.11.5.1 stores the (1) MySQL username, (2) password, and the (2) Blowfish secret key in plaintext in the /tmp Session file, which allows local users to obtain sensitive information.

More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1567)