Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-2505

Опубликовано: 14 июл. 2011
Источник: debian
EPSS Средний

Описание

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phpmyadminfixed4:3.4.3.1-1package
phpmyadminnot-affectedlennypackage

EPSS

Процентиль: 98%
0.47906
Средний

Связанные уязвимости

ubuntu
больше 14 лет назад

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

nvd
больше 14 лет назад

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

github
больше 3 лет назад

phpMyAdmin remote variable manipulation

EPSS

Процентиль: 98%
0.47906
Средний