Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpMyAdmin 'server_databases.php' 远程命令执行漏洞
Vulnerability Description
phpMyAdmin 2.11.7.1之前版本中存在跨站请求伪造漏洞。远程攻击者通过对(1) "创建一个数据库" 功能(db_create.php)中的db 参数 , 和 (2) 与修改连接字符集的未明程序有关的convcharset 和 collation_connection 参数中的一个链接或IMG标签来执行未认证操作。
CVSS Information
N/A
Vulnerability Type
N/A