Announcement-ID: PMASA-2008-5
Date: 2008-07-15
Updated: 2008-07-16
XSRF/CSRF for creating a database and modifying user charset
We received an advisory from Aung Khant (YGN Ethical Hacker Group), and we wish to thank him for his work. A logged-in user, if abused into clicking a crafted link or loading an attack page, would create a database he did not intend to, or would change his connection character set.
We consider this vulnerability to be serious.
Versions before 2.11.7.1.
Upgrade to phpMyAdmin 2.11.7.1 or newer.
These advisories are available from the reporter:
http://yehg.net/lab/pr0js/advisories/XSRF_CreateDB_inPhpMyAdmin2.11.7.pdf
http://yehg.net/lab/pr0js/advisories/XSRF_ConvertCharset_inPhpMyAdmin2.11.7.pdf
Assigned CVE ids: CVE-2008-3197
Revisions 11389 and 11391 were applied on the MAINT_2_11_7 branch:
Revision 11389
Revision 11391
For further information and in case of questions, please contact the phpMyAdmin team. Our website is http://www.phpmyadmin.net.