|
The phpMyAdmin protects cross-site framing only in index.php page. Due to its frame-friendly pages, it cannot protect framing to other pages by third-parties. Cross-site Framing is controlled by index.php. Attackers may take advantage of this and can do phishing or fooling user if the victim has authenticated. Cross-frame reading access is denied but a zero-day exploit can read across/control several frames contents.
|