Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-3239

Опубликовано: 26 апр. 2013
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 4.6

Описание

phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.

РелизСтатусПримечание
devel

not-affected

4:3.5.8.1-1
esm-apps/xenial

not-affected

4:3.5.8.1-1
esm-infra-legacy/trusty

not-affected

4:3.5.8.1-1
hardy

ignored

end of life
lucid

ignored

end of life
oneiric

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

ignored

end of life
raring

not-affected

Показывать по

EPSS

Процентиль: 94%
0.16133
Средний

4.6 Medium

CVSS2

Связанные уязвимости

nvd
около 12 лет назад

phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.

debian
около 12 лет назад

phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir ...

CVSS3: 8.5
github
около 3 лет назад

phpMyAdmin Remote Code Execution

EPSS

Процентиль: 94%
0.16133
Средний

4.6 Medium

CVSS2