7.5
CVSSv2

CVE-2011-2506

Published: 14/07/2011 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x prior to 3.3.10.2 and 3.4.x prior to 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote malicious users to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 3.0.1.1

phpmyadmin phpmyadmin 3.2.1

phpmyadmin phpmyadmin 3.3.10.0

phpmyadmin phpmyadmin 3.1.4

phpmyadmin phpmyadmin 3.1.3

phpmyadmin phpmyadmin 3.3.8.1

phpmyadmin phpmyadmin 3.2.0

phpmyadmin phpmyadmin 3.3.10.1

phpmyadmin phpmyadmin 3.1.2

phpmyadmin phpmyadmin 3.1.0

phpmyadmin phpmyadmin 3.3.3.0

phpmyadmin phpmyadmin 3.0.0

phpmyadmin phpmyadmin 3.3.4.0

phpmyadmin phpmyadmin 3.3.9.2

phpmyadmin phpmyadmin 3.3.1.0

phpmyadmin phpmyadmin 3.3.7

phpmyadmin phpmyadmin 3.1.5

phpmyadmin phpmyadmin 3.1.1

phpmyadmin phpmyadmin 3.3.5.0

phpmyadmin phpmyadmin 3.3.0.0

phpmyadmin phpmyadmin 3.3.6

phpmyadmin phpmyadmin 3.3.2.0

phpmyadmin phpmyadmin 3.3.9.0

phpmyadmin phpmyadmin 3.1.3.2

phpmyadmin phpmyadmin 3.3.5.1

phpmyadmin phpmyadmin 3.3.9.1

phpmyadmin phpmyadmin 3.0.1

phpmyadmin phpmyadmin 3.1.3.1

phpmyadmin phpmyadmin 3.3.8

phpmyadmin phpmyadmin 3.2.2

phpmyadmin phpmyadmin 3.4.0.0

phpmyadmin phpmyadmin 3.4.1.0

phpmyadmin phpmyadmin 3.4.2.0

phpmyadmin phpmyadmin 3.4.3.0

Vendor Advisories

Several vulnerabilities were discovered in phpMyAdmin, a tool to administrate MySQL over the web The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-2505 Possible session manipulation in Swekey authentication CVE-2011-2506 Possible code injection in setup script, in case session variables are compro ...

Exploits

<?php /* # Exploit Title: phpMyAdmin 3x Swekey Remote Code Injection Exploit # Date: 2011-07-09 # Author: Mango of haxxorse # Version: phpMyAdmin < 33102 || phpMyAdmin < 3431 # CVE : CVE-2011-2505, CVE-2011-2506 # Advisory: wwwxxorse/advisories/phpMyAdmin_3x_Multiple_Remote_Code_Executionstxt # Details: haxxor ...
#!/usr/bin/env python # coding=utf-8 # pma3 - phpMyAdmin3 remote code execute exploit # Author: wofeiwo<wofeiwo@80seccom> # Thx Superhei # Tested on: 311, 321, 343 # CVE: CVE-2011-2505, CVE-2011-2506 # Date: 2011-07-08 # Have fun, DO *NOT* USE IT TO DO BAD THING ################################################ # Requirements: 1 "con ...
Remote code execution exploit for phpMyAdmin versions below 33102 and 3431 ...
phpMyAdmin Swekey remote code injection exploit that affects versions prior to 3431 and versions prior to 33102 ...
phpMyAdmin version 3x suffers from multiple remote code execution vulnerabilities ...