LWN.net Logo

phpMyAdmin: cross-site framing vulnerability

Package(s):phpMyAdmin CVE #(s):
Created:July 31, 2008 Updated:August 6, 2008
Description: phpMyAdmin has a cross-site framing vulnerability, described here: "It was permitted to display phpMyAdmin's frames inside another page, opening phishing or fooling possibilities; now, a parameter AllowThirdPartyFraming must be set to true in config.inc.php to allow this behavior. Also, XSS was possible for someone who could overwrite config/config.inc.php during the time this file is present in this directory."
Alerts:
Fedora FEDORA-2008-6868 2008-07-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds