6.5
CVSSv2

CVE-2013-5003

Published: 31/07/2013 Updated: 31/12/2016
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x prior to 3.5.8.2 and 4.0.x prior to 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 3.5.8

phpmyadmin phpmyadmin 3.5.2.2

phpmyadmin phpmyadmin 3.5.8.1

phpmyadmin phpmyadmin 3.5.7

phpmyadmin phpmyadmin 3.5.6

phpmyadmin phpmyadmin 3.5.2.1

phpmyadmin phpmyadmin 3.5.2.0

phpmyadmin phpmyadmin 3.5.1.0

phpmyadmin phpmyadmin 3.5.0.0

phpmyadmin phpmyadmin 3.5.3.0

phpmyadmin phpmyadmin 3.5.5

phpmyadmin phpmyadmin 3.5.4

phpmyadmin phpmyadmin 4.0.1

phpmyadmin phpmyadmin 4.0.0

phpmyadmin phpmyadmin 4.0.3

phpmyadmin phpmyadmin 4.0.2

phpmyadmin phpmyadmin 4.0.4

phpmyadmin phpmyadmin 4.0.4.1

Vendor Advisories

Several vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-4995 Authenticated users could inject arbitrary web script or HTML via a crafted SQL query CVE-2013-4996 Cross site scripting was possible via ...

Github Repositories

The prototype implementation of our USENIX 2023 paper

Minimalist This repository contains the code for our prototype implementation of Minimalist, described in our USENIX 2023 paper Minimalist is a semi-automated approach to debloat PHP web applications Here, we provide instructions for building Minimalist's individual components Folder Organization The folder organization is listed below |-- basic_testsh # Runs i