[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-2507Date: (C)2011-07-14   (M)2023-12-22


libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION superglobal array.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.5
Exploit Score: 8.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://www.securityfocus.com/archive/1/518804/100/0/threaded
SECUNIA-45139
SECUNIA-45292
SECUNIA-45315
OSVDB-73613
SREASON-8306
DSA-2286
FEDORA-2011-9144
MDVSA-2011:124
http://www.openwall.com/lists/oss-security/2011/06/28/2
http://www.openwall.com/lists/oss-security/2011/06/28/6
http://www.openwall.com/lists/oss-security/2011/06/28/8
http://www.openwall.com/lists/oss-security/2011/06/29/11
http://0x6a616d6573.blogspot.com/2011/07/phpmyadmin-fud.html
http://ha.xxor.se/2011/07/phpmyadmin-3x-multiple-remote-code.html
http://ha.xxor.se/2011/07/phpmyadmin-3x-pregreplace-rce-poc.html
http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commit%3Bh=69fb0f8e7dc38075427aceaf09bcac697d0590ff
http://typo3.org/teams/security/security-bulletins/typo3-sa-2011-008/
http://www.phpmyadmin.net/home_page/security/PMASA-2011-7.php
http://www.xxor.se/advisories/phpMyAdmin_3.x_Multiple_Remote_Code_Executions.txt

CPE    47
cpe:/a:phpmyadmin:phpmyadmin:3.0.0:rc1
cpe:/a:phpmyadmin:phpmyadmin:3.1.2
cpe:/a:phpmyadmin:phpmyadmin:3.1.3
cpe:/a:phpmyadmin:phpmyadmin:3.1.4
...
CWE    1
CWE-94
OVAL    1
oval:org.secpod.oval:def:600595

© SecPod Technologies