CVE-2008-1567

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:7:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:opensuse:opensuse:10.2:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:10.3:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-03-31 22:44

Updated : 2024-02-14 15:31


NVD link : CVE-2008-1567

Mitre link : CVE-2008-1567

CVE.ORG link : CVE-2008-1567


JSON object : View

Products Affected

opensuse

  • opensuse

debian

  • debian_linux

phpmyadmin

  • phpmyadmin

fedoraproject

  • fedora
CWE
CWE-312

Cleartext Storage of Sensitive Information