PT-2011-2795 · Phpmyadmin · Phpmyadmin

Publicado

2011-02-14

·

Atualizado

2017-08-17

·

CVE-2011-0987

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 2.11.x through 2.11.11.2 phpMyAdmin versions 3.3.x through 3.3.9.1
Description The issue is related to the PMA Bookmark get function in phpMyAdmin, which does not properly restrict bookmark queries. This makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.
Recommendations For phpMyAdmin versions 2.11.x through 2.11.11.2, update to version 2.11.11.3 or later. For phpMyAdmin versions 3.3.x through 3.3.9.1, update to version 3.3.9.2 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-0987
DSA-2167-1

Produtos afetados

Phpmyadmin