Medium severity5.5NVD Advisory· Published Mar 31, 2008· Updated Apr 23, 2026
CVE-2008-1567
CVE-2008-1567
Description
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
Affected products
7- cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:7:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:7:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- www.debian.org/security/2008/dsa-1557nvdMailing ListPatch
- www.phpmyadmin.net/home_page/security.phpnvdPatchVendor Advisory
- www.securityfocus.com/bid/28560nvdBroken LinkPatchThird Party AdvisoryVDB Entry
- secunia.com/advisories/29588nvdBroken LinkVendor Advisory
- secunia.com/advisories/29613nvdBroken LinkVendor Advisory
- secunia.com/advisories/29964nvdBroken LinkVendor Advisory
- secunia.com/advisories/30816nvdBroken LinkVendor Advisory
- secunia.com/advisories/32834nvdBroken LinkVendor Advisory
- secunia.com/advisories/33822nvdBroken LinkVendor Advisory
- sourceforge.net/tracker/index.phpnvdIssue TrackingThird Party Advisory
- www.vupen.com/english/advisories/2008/1037/referencesnvdBroken LinkVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/41541nvdThird Party AdvisoryVDB Entry
- lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlnvdMailing List
- lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.htmlnvdMailing List
- www.mandriva.com/security/advisoriesnvdBroken Link
- www.redhat.com/archives/fedora-package-announce/2008-April/msg00031.htmlnvdMailing List
- www.redhat.com/archives/fedora-package-announce/2008-April/msg00080.htmlnvdMailing List
News mentions
0No linked articles in our index yet.