Title : phpMyAdmin Multiple Cross-Site Request Forgery Vulnerabilities VUPEN ID : VUPEN/ADV-2008-2116 CVE ID : CVE-2008-3197 CWE ID : CWE-352
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-07-16
Technical Description
Multiple vulnerabilities have been identified in phpMyAdmin, which could be exploited by attackers to manipulate certain data. These issues are caused by errors in the "index.php" and "db_create.php" scripts that do not validate user-supplied data and HTTP requests, which could be exploited by attackers to conduct cross-site request forgery attacks and trick a user into following a malicious URL to create arbitrary databases or change the connection character set.