Novell Home

CVE-2008-1924

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2008-1924 at MITRE

Description

Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variable.

NVD CVSS v2 Base Score: 3.5 (AV:N/AC:M/Au:S/C:P/I:N/A:N)

Novell/SUSE information

Novell Bugzilla entry: 383135, 410768

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 10.2
  • phpMyAdmin >= 2.9.1.1-9
openSUSE 10.3
  • phpMyAdmin >= 2.11.9-0.1
openSUSE 10.3
  • phpMyAdmin >= 2.11.9.4-0.1

© 2012 Novell