Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpMyAdmin table参数SQL注入漏洞
Vulnerability Description
phpMyAdmin是用PHP编写的工具,用于通过WEB管理MySQL。 phpMyAdmin 2.11.x 2.11.9.4 以前版本和 3.x 3.1.1.0以前版本存在跨站伪造漏洞,允许未授权的攻击者以管理员身份通过 tbl_structure.php 的link和IMG标签执行未授权的任务。
CVSS Information
N/A
Vulnerability Type
N/A