[Forgot Password]
Login  Register Subscribe

23631

 
 

115084

 
 

97147

 
 

909

 
 

78730

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2011-2718

Date: (C)2011-08-01   (M)2017-08-29 


Multiple directory traversal vulnerabilities in the relational schema implementation in phpMyAdmin 3.4.x before 3.4.3.2 allow remote authenticated users to include and execute arbitrary local files via directory traversal sequences in an export type field, related to (1) libraries/schema/User_Schema.class.php and (2) schema_export.php.

CVSS Score: 6.0Access Vector: NETWORK
Exploit Score: 6.8Access Complexity: MEDIUM
Impact Score: 6.4Authentication: SINGLE_INSTANCE
 Confidentiality: PARTIAL
 Integrity: PARTIAL
 Availability: PARTIAL





Reference:
SECUNIA-45365
SECUNIA-45515
BID-48874
OSVDB-74111
FEDORA-2011-9725
FEDORA-2011-9734
MDVSA-2011:124
http://www.openwall.com/lists/oss-security/2011/07/25/4
http://www.openwall.com/lists/oss-security/2011/07/26/10
http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commit;h=3ae58f0cd6b89ad4767920f9b214c38d3f6d4393
http://www.phpmyadmin.net/home_page/security/PMASA-2011-11.php
https://bugzilla.redhat.com/show_bug.cgi?id=725383
phpmyadmin-schema-file-include(68768)

CPE    5
cpe:/a:phpmyadmin:phpmyadmin:3.4.0.0
cpe:/a:phpmyadmin:phpmyadmin:3.4.1.0
cpe:/a:phpmyadmin:phpmyadmin:3.4.2.0
cpe:/a:phpmyadmin:phpmyadmin:3.4.3.0
...
CWE    1
CWE-22
OVAL    2
oval:org.secpod.oval:def:102891
oval:org.secpod.oval:def:102782

© 2013 SecPod Technologies