|Date: (C)2011-08-01 (M)2017-08-29|| |
libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 188.8.131.52 and 3.4.x before 184.108.40.206 does not properly manage sessions associated with Swekey authentication, which allows remote attackers to modify the SESSION superglobal array, other superglobal arrays, and certain swekey.auth.lib.php local variables via a crafted query string, a related issue to CVE-2011-2505.
|CVSS Score: 6.4||Access Vector: NETWORK|
|Exploit Score: 10.0||Access Complexity: LOW|
|Impact Score: 4.9||Authentication: NONE|
| ||Confidentiality: NONE|
| ||Integrity: PARTIAL|
| ||Availability: PARTIAL|