6.5
CVSSv2

CVE-2011-2507

Published: 14/07/2011 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x prior to 3.3.10.2 and 3.4.x prior to 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION superglobal array.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 3.0.1.1

phpmyadmin phpmyadmin 3.2.1

phpmyadmin phpmyadmin 3.3.10.0

phpmyadmin phpmyadmin 3.1.4

phpmyadmin phpmyadmin 3.1.3

phpmyadmin phpmyadmin 3.3.8.1

phpmyadmin phpmyadmin 3.2.0

phpmyadmin phpmyadmin 3.3.10.1

phpmyadmin phpmyadmin 3.1.2

phpmyadmin phpmyadmin 3.1.0

phpmyadmin phpmyadmin 3.3.3.0

phpmyadmin phpmyadmin 3.0.0

phpmyadmin phpmyadmin 3.3.4.0

phpmyadmin phpmyadmin 3.3.9.2

phpmyadmin phpmyadmin 3.3.1.0

phpmyadmin phpmyadmin 3.3.7

phpmyadmin phpmyadmin 3.1.5

phpmyadmin phpmyadmin 3.1.1

phpmyadmin phpmyadmin 3.3.5.0

phpmyadmin phpmyadmin 3.3.0.0

phpmyadmin phpmyadmin 3.3.6

phpmyadmin phpmyadmin 3.3.2.0

phpmyadmin phpmyadmin 3.3.9.0

phpmyadmin phpmyadmin 3.1.3.2

phpmyadmin phpmyadmin 3.3.5.1

phpmyadmin phpmyadmin 3.3.9.1

phpmyadmin phpmyadmin 3.0.1

phpmyadmin phpmyadmin 3.1.3.1

phpmyadmin phpmyadmin 3.3.8

phpmyadmin phpmyadmin 3.2.2

phpmyadmin phpmyadmin 3.4.0.0

phpmyadmin phpmyadmin 3.4.1.0

phpmyadmin phpmyadmin 3.4.2.0

phpmyadmin phpmyadmin 3.4.3.0

Vendor Advisories

Several vulnerabilities were discovered in phpMyAdmin, a tool to administrate MySQL over the web The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-2505 Possible session manipulation in Swekey authentication CVE-2011-2506 Possible code injection in setup script, in case session variables are compro ...

Exploits

phpMyAdmin version 3x suffers from multiple remote code execution vulnerabilities ...