Security Advisory
CVE-2008-1567
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.