6.4
CVSSv2

CVE-2011-2505

Published: 14/07/2011 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 650
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x prior to 3.3.10.2 and 3.4.x prior to 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote malicious users to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 3.0.1.1

phpmyadmin phpmyadmin 3.2.1

phpmyadmin phpmyadmin 3.3.10.0

phpmyadmin phpmyadmin 3.1.4

phpmyadmin phpmyadmin 3.1.3

phpmyadmin phpmyadmin 3.3.8.1

phpmyadmin phpmyadmin 3.2.0

phpmyadmin phpmyadmin 3.3.10.1

phpmyadmin phpmyadmin 3.1.2

phpmyadmin phpmyadmin 3.1.0

phpmyadmin phpmyadmin 3.3.3.0

phpmyadmin phpmyadmin 3.0.0

phpmyadmin phpmyadmin 3.3.4.0

phpmyadmin phpmyadmin 3.3.9.2

phpmyadmin phpmyadmin 3.3.1.0

phpmyadmin phpmyadmin 3.3.7

phpmyadmin phpmyadmin 3.1.5

phpmyadmin phpmyadmin 3.1.1

phpmyadmin phpmyadmin 3.3.5.0

phpmyadmin phpmyadmin 3.3.0.0

phpmyadmin phpmyadmin 3.3.6

phpmyadmin phpmyadmin 3.3.2.0

phpmyadmin phpmyadmin 3.3.9.0

phpmyadmin phpmyadmin 3.1.3.2

phpmyadmin phpmyadmin 3.3.5.1

phpmyadmin phpmyadmin 3.3.9.1

phpmyadmin phpmyadmin 3.0.1

phpmyadmin phpmyadmin 3.1.3.1

phpmyadmin phpmyadmin 3.3.8

phpmyadmin phpmyadmin 3.2.2

phpmyadmin phpmyadmin 3.4.0.0

phpmyadmin phpmyadmin 3.4.1.0

phpmyadmin phpmyadmin 3.4.2.0

phpmyadmin phpmyadmin 3.4.3.0

Vendor Advisories

Several vulnerabilities were discovered in phpMyAdmin, a tool to administrate MySQL over the web The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-2505 Possible session manipulation in Swekey authentication CVE-2011-2506 Possible code injection in setup script, in case session variables are compro ...

Exploits

<?php /* # Exploit Title: phpMyAdmin 3x Swekey Remote Code Injection Exploit # Date: 2011-07-09 # Author: Mango of haxxorse # Version: phpMyAdmin < 33102 || phpMyAdmin < 3431 # CVE : CVE-2011-2505, CVE-2011-2506 # Advisory: wwwxxorse/advisories/phpMyAdmin_3x_Multiple_Remote_Code_Executionstxt # Details: haxxor ...
#!/usr/bin/env python # coding=utf-8 # pma3 - phpMyAdmin3 remote code execute exploit # Author: wofeiwo<wofeiwo@80seccom> # Thx Superhei # Tested on: 311, 321, 343 # CVE: CVE-2011-2505, CVE-2011-2506 # Date: 2011-07-08 # Have fun, DO *NOT* USE IT TO DO BAD THING ################################################ # Requirements: 1 "con ...
Remote code execution exploit for phpMyAdmin versions below 33102 and 3431 ...
phpMyAdmin Swekey remote code injection exploit that affects versions prior to 3431 and versions prior to 33102 ...
phpMyAdmin version 3x suffers from multiple remote code execution vulnerabilities ...