PT-2011-3904 · Phpmyadmin · Phpmyadmin

Frans Pehrson

·

Publicado

2011-07-14

·

Atualizado

2022-05-14

·

CVE-2011-2505

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 3.x prior to 3.3.10.2 phpMyAdmin versions 3.4.x prior to 3.4.3.1
Description The Swekey authentication feature in phpMyAdmin assigns values to arbitrary parameters referenced in the query string, allowing remote attackers to modify the SESSION superglobal array via a crafted request. This issue is related to a remote variable manipulation vulnerability.
Recommendations For phpMyAdmin versions 3.x prior to 3.3.10.2, update to version 3.3.10.2 or later. For phpMyAdmin versions 3.4.x prior to 3.4.3.1, update to version 3.4.3.1 or later.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2505
DSA-2286-1
GHSA-VQCM-R62W-W437

Produtos afetados

Phpmyadmin