Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpMyAdmin '$_REQUEST' SQL注入漏洞
Vulnerability Description
phpMyAdmin 2.11.5之前的版本访问$_REQUEST而获得一些非$_GET和$_POST的参数,这使得同一个域中的攻击者可以借助特制的cookies,无视某些变量,执行SQL注入和跨站请求伪造攻击。
CVSS Information
N/A
Vulnerability Type
N/A