PT-2011-3906 · Phpmyadmin · Phpmyadmin

Frans Pehrson

·

Published

2011-07-14

·

Updated

2018-10-09

·

CVE-2011-2507

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 3.x prior to 3.3.10.2 phpMyAdmin versions 3.4.x prior to 3.4.3.1
Description The issue is related to the Synchronize implementation in phpMyAdmin, where the libraries/server synchronize.lib.php file does not properly quote regular expressions. This allows remote authenticated users to inject a PCRE e (aka PREG REPLACE EVAL) modifier, which can lead to the execution of arbitrary PHP code. The exploitation is possible by modifying the SESSION superglobal array.
Recommendations For phpMyAdmin versions 3.x prior to 3.3.10.2, update to version 3.3.10.2 or later. For phpMyAdmin versions 3.4.x prior to 3.4.3.1, update to version 3.4.3.1 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2507
DSA-2286-1

Affected Products

Phpmyadmin