>> phpMyAdmin Session Data Information Disclosure Vulnerability
Title : phpMyAdmin Session Data Information Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2008-1037 CVE ID : CVE-2008-1567
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-31
Technical Description
A vulnerability has been identified in phpMyAdmin, which could be exploited by attackers to gain knowledge of sensitive information. This issue is caused by a design error where sensitive information (e.g. MySQL username and password, or the Blowfish secret key) is stored in session data, which could be exploited by attackers to disclose information on a shared host.