Vulnerability Details CVE-2009-4605
scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 63.4%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2009-4605
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.1.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.1.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.1.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.2.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.2.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.2.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.3.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.4.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.5.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.5.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.5.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.6.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.7.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.7.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.8.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.9.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.9.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.9.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.9.3
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.9.4
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.9.5
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.9.6