Описание
libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated with Swekey authentication, which allows remote attackers to modify the SESSION superglobal array, other superglobal arrays, and certain swekey.auth.lib.php local variables via a crafted query string, a related issue to CVE-2011-2505.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 4:3.4.3.2-1 |
hardy | ignored | end of life |
lucid | ignored | end of life |
maverick | ignored | end of life |
natty | ignored | end of life |
oneiric | not-affected | 4:3.4.3.2-1 |
precise | not-affected | 4:3.4.3.2-1 |
quantal | not-affected | 4:3.4.3.2-1 |
raring | not-affected | 4:3.4.3.2-1 |
saucy | not-affected | 4:3.4.3.2-1 |
Показывать по
6.4 Medium
CVSS2
Связанные уязвимости
libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated with Swekey authentication, which allows remote attackers to modify the SESSION superglobal array, other superglobal arrays, and certain swekey.auth.lib.php local variables via a crafted query string, a related issue to CVE-2011-2505.
libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3 ...
libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated with Swekey authentication, which allows remote attackers to modify the SESSION superglobal array, other superglobal arrays, and certain swekey.auth.lib.php local variables via a crafted query string, a related issue to CVE-2011-2505.
6.4 Medium
CVSS2