Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2008-3456 | First vendor Publication | 2008-08-04 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.4 | Attack Range | Network |
Cvss Impact Score | 4.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3456 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-59 | Improper Link Resolution Before File Access ('Link Following') |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-02-17 | Name : Fedora Update for phpMyAdmin FEDORA-2008-6868 File : nvt/gb_fedora_2008_6868_phpMyAdmin_fc9.nasl |
2008-12-03 | Name : Debian Security Advisory DSA 1675-1 (phpmyadmin) File : nvt/deb_1675_1.nasl |
2008-09-24 | Name : Debian Security Advisory DSA 1641-1 (phpmyadmin) File : nvt/deb_1641_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
47486 | phpMyAdmin setup.php Cross-Frame Scripting The phpMyAdmin protects cross-site framing only in index.php page. Due to its frame-friendly pages, it cannot protect framing to other pages by third-parties. Cross-site Framing is controlled by index.php. Attackers may take advantage of this and can do phishing or fooling user if the victim has authenticated. Cross-frame reading access is denied but a zero-day exploit can read across/control several frames contents. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2008-12-03 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1675.nasl - Type : ACT_GATHER_INFO |
2008-11-18 | Name : The remote openSUSE host is missing a security update. File : suse_phpMyAdmin-5781.nasl - Type : ACT_GATHER_INFO |
2008-09-23 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1641.nasl - Type : ACT_GATHER_INFO |
2008-07-31 | Name : The remote Fedora host is missing a security update. File : fedora_2008-6810.nasl - Type : ACT_GATHER_INFO |
2008-07-31 | Name : The remote Fedora host is missing a security update. File : fedora_2008-6868.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:13:45 |
|
2024-11-28 12:16:12 |
|
2021-05-04 12:07:52 |
|
2021-04-22 01:08:13 |
|
2020-05-23 01:39:47 |
|
2020-05-23 00:22:03 |
|
2018-11-27 12:02:29 |
|
2018-08-15 12:02:18 |
|
2017-08-08 09:24:17 |
|
2016-04-26 17:42:05 |
|
2014-02-17 10:45:54 |
|
2013-05-11 00:22:42 |
|