← Retour aux CVEs
CVE-2008-3456
N/ADescription
phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.
Details CVE
Score CVSS v3.1N/A
Publie8/4/2008
Derniere modification4/23/2026
Sourcenvd
Observations honeypot0
Produits affectes
phpmyadmin:phpmyadmin
Faiblesses (CWE)
CWE-59
References
http://secunia.com/advisories/31263(cve@mitre.org)
http://secunia.com/advisories/31312(cve@mitre.org)
http://secunia.com/advisories/32834(cve@mitre.org)
http://www.debian.org/security/2008/dsa-1641(cve@mitre.org)
http://www.securityfocus.com/bid/30420(cve@mitre.org)
http://www.vupen.com/english/advisories/2008/2226/references(cve@mitre.org)
https://exchange.xforce.ibmcloud.com/vulnerabilities/44050(cve@mitre.org)
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/31263(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/31312(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/32834(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2008/dsa-1641(af854a3a-2127-422b-91ae-364da2661108)
http://www.mandriva.com/security/advisories?name=MDVSA-2008:202(af854a3a-2127-422b-91ae-364da2661108)
http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-6(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/30420(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2008/2226/references(af854a3a-2127-422b-91ae-364da2661108)
http://yehg.net/lab/pr0js/advisories/Cross-Site_Framing_inphpMyAdmin2.11.7.pdf(af854a3a-2127-422b-91ae-364da2661108)
https://exchange.xforce.ibmcloud.com/vulnerabilities/44050(af854a3a-2127-422b-91ae-364da2661108)
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01239.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01316.html(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.