Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Michal Čihař

#25001de 53,639
9.8CVSS total
Vulnerabilidades · 1
PT-2016-6664
9.8
2014-05-05
Phpmyadmin · Phpmyadmin · CVE-2016-5734
**Name of the Vulnerable Software and Affected Versions** phpMyAdmin versions 4.0.x through 4.0.10.15 phpMyAdmin versions 4.4.x through 4.4.15.6 phpMyAdmin versions 4.6.x through 4.6.2 **Description** The issue arises from improper delimiter selection, which could allow remote attackers to execute arbitrary PHP code via a crafted string. This is demonstrated by the table search-and-replace implementation, potentially leveraging the preg replace e (aka eval) modifier. **Recommendations** For phpMyAdmin versions 4.0.x through 4.0.10.15, update to version 4.0.10.16 or later. For phpMyAdmin versions 4.4.x through 4.4.15.6, update to version 4.4.15.7 or later. For phpMyAdmin versions 4.6.x through 4.6.2, update to version 4.6.3 or later.