PT-2013-5163 · Php · Phpmyadmin

Markus Wulftange

·

Publicado

2013-07-04

·

Atualizado

2024-06-15

·

CVE-2013-4729

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 4.0.0 through 4.0.4
Description The issue allows remote authenticated users to modify the GLOBALS superglobal array and change the configuration via a crafted request. This is due to the import.php file in phpMyAdmin not properly restricting the ability of input data to specify a file format.
Recommendations For phpMyAdmin versions 4.0.0 through 4.0.4, update to version 4.0.4.1 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4729
GHSA-X962-W72P-MV7Q
OPENSUSE-SU-2024:10054-1

Produtos afetados

Phpmyadmin