CVE DATABASE / CVE-2008-1567
CVE-2008-1567
CVSS 5.5 · MEDIUM
Summary
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
CVSS 3.1 breakdown
| Base score | 5.5 (MEDIUM) |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| Attack vector | LOCAL |
| Attack complexity | LOW |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity | NONE |
| Availability | NONE |
Weakness type (CWE)
Affected products
Phpmyadmin phpmyadminDebian debian linuxFedoraproject fedoraOpensuse opensuse
Check this CVE live
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
References
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html
- http://secunia.com/advisories/29588
- http://secunia.com/advisories/29613
- http://secunia.com/advisories/29964
- http://secunia.com/advisories/30816
- http://secunia.com/advisories/32834
- http://secunia.com/advisories/33822
- http://sourceforge.net/tracker/index.php?func=detail&aid=1909711&group_id=23067&atid=377408
- http://www.debian.org/security/2008/dsa-1557
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:131
- http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-2
- http://www.securityfocus.com/bid/28560
- http://www.vupen.com/english/advisories/2008/1037/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41541
Data: NIST NVD. NVD last modified 2026-04-23. Always verify against the vendor advisory before acting.