VDB
CVE-2008-3456
CVE-2008-3456
PUBLISHED
CVSS 6.400000095367432 MEDIUM
phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.
EPSS 1.71% · 82.7th percentile
Risk Scores
CVSS 2.0
6.400000095367432
EPSS Score
1.71%
82.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| phpmyadmin | phpmyadmin | 2.1, 2.0, 2.0.0 |
| n/a | n/a | n/a |
Timeline
- Aug 4, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- http://secunia.com/advisories/31312 technical
- http://secunia.com/advisories/32834 technical
- http://www.debian.org/security/2008/dsa-1641 technical
- MDVSA-2008:202 vendor-advisory
- FEDORA-2008-6868 vendor-advisory
- http://yehg.net/lab/pr0js/advisories/Cross-Site_Framing_inphpMyAdmin2.11.7.pdf url
- FEDORA-2008-6810 vendor-advisory
- phpmyadmin-multiple-weak-security(44050) vdb
- ADV-2008-2226 vdb
- 31263 third-party-advisory
- http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-6 url
- 30420 vdb
- SUSE-SR:2008:026 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2008-3456 advisory