[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96125

 
 

909

 
 

78020

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2011-2719

Date: (C)2011-08-01   (M)2017-08-29
 
CVSS Score: 6.4Access Vector: NETWORK
Exploitability Subscore: 10.0Access Complexity: LOW
Impact Subscore: 4.9Authentication: NONE
 Confidentiality: NONE
 Integrity: PARTIAL
 Availability: PARTIAL











libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated with Swekey authentication, which allows remote attackers to modify the SESSION superglobal array, other superglobal arrays, and certain swekey.auth.lib.php local variables via a crafted query string, a related issue to CVE-2011-2505.

Reference:
http://www.securityfocus.com/archive/1/archive/1/518967/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/519155/100/0/threaded
SECUNIA-45315
SECUNIA-45365
SECUNIA-45515
BID-48874
OSVDB-74112
SREASON-8322
DSA-2286
FEDORA-2011-9725
FEDORA-2011-9734
MDVSA-2011:124
http://www.openwall.com/lists/oss-security/2011/07/25/4
http://www.openwall.com/lists/oss-security/2011/07/26/10
http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commit;h=571cdc6ff4bf375871b594f4e06f8ad3159d1754
http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commit;h=e7bb42c002885c2aca7aba4d431b8c63ae4de9b7
http://www.phpmyadmin.net/home_page/security/PMASA-2011-12.php
http://www.xxor.se/advisories/phpMyAdmin_3.x_Conditional_Session_Manipulation.txt
https://bugzilla.redhat.com/show_bug.cgi?id=725384
phpmyadmin-swekey-file-overwrite(68769)

CPE    48
cpe:/a:phpmyadmin:phpmyadmin:3.0.0:rc1
cpe:/a:phpmyadmin:phpmyadmin:3.1.4
cpe:/a:phpmyadmin:phpmyadmin:3.1.5
cpe:/a:phpmyadmin:phpmyadmin:3.0.0:beta
...
CWE    1
CWE-20
OVAL    2
oval:org.secpod.oval:def:102782
oval:org.secpod.oval:def:102891

© 2013 SecPod Technologies