Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-5621

25
FAUCET Score

CVE-2008-5621 describes a Cross-Site Request Forgery (CSRF) vulnerability in phpMyAdmin versions 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0, allowing remote attackers to execute unauthorized actions as an administrator. This vulnerability has a CVSS score of 6.0 (Medium), indicating that an authenticated user could be tricked into performing actions with partial confidentiality, integrity, and availability impacts. While not observed in active exploitation (KEV: No), public exploit code exists on ExploitDB, and it can be leveraged for SQL injection and arbitrary code execution.

Impacted Technologies

VendorProductVersion(s)CPE
2.11.0CPE matchmatch criteria
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.0:*:*:*:*:*:*:*
2.11.0.0CPE matchmatch criteria
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.0.0:*:*:*:*:*:*:*
2.11.1CPE matchmatch criteria
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.1:*:*:*:*:*:*:*
2.11.1.0CPE matchmatch criteria
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.1.0:*:*:*:*:*:*:*
2.11.1.1CPE matchmatch criteria
cpe:2.3:a:phpmyadmin:phpmyadmin:2.11.1.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.0MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
SINGLE
Exploitability Score
6.8
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.15%
Probability of exploitation in next 30 days
EPSS Percentile
80.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-7382 · Dec 8, 2008
This CVE's current EPSS score of 0.0215 is in the 87th percentile among its peer group of 1,428 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2008-5621

phpMyAdmin: SQL injection through XSRF on several pages (PMASA-2008-10)

References

lists.opensuse.org / opensuse-security-announce/2009-02/msg00000.html
osvdb.org / 50894
secunia.com / advisories/33076
Vendor Advisory
secunia.com / advisories/33146
Vendor Advisory
secunia.com / advisories/33246
Vendor Advisory
secunia.com / advisories/33822
Vendor Advisory
secunia.com / advisories/33912
Vendor Advisory
security.gentoo.org / glsa/glsa-200903-32.xml
securityreason.com / securityalert/4753
exchange.xforce.ibmcloud.com / vulnerabilities/47168
exploit-db.com / exploits/7382
redhat.com / archives/fedora-package-announce/2008-December/msg00784.html
typo3.org / teams/security/security-bulletins/typo3-20081222-1
debian.org / security/2009/dsa-1723
openwall.com / lists/oss-security/2009/02/12/1
phpmyadmin.net / home_page/security/PMASA-2008-10.php
PatchVendor Advisory
securityfocus.com / bid/32720
Patch
vupen.com / english/advisories/2008/3402
vupen.com / english/advisories/2008/3501
Vendor Advisory