CVE-2015-3638
Summary
| CVE | CVE-2015-3638 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-07-21 14:29:00 UTC |
| Updated | 2017-07-25 16:35:00 UTC |
| Description | phpMyBackupPro before 2.5 does not validate integer input, which allows remote authenticated users to execute arbitrary PHP code by injecting scripts via the path, filename, and period parameters to scheduled.php, and making requests to injected scripts, or by injecting PHP into a PHP configuration variable via a PHP variable variable. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Phpmybackuppro | Phpmybackuppro | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: CVE requests / Advisory: phpMyBackupPro | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| oss-security - CVE requests / Advisory: phpMyBackupPro | MLIST | openwall.com | Mailing List, Patch, Third Party Advisory |
| phpMyBackupPro Bugs Lets Remote Users Inject SQL Commands and Remote Authenticated Users Execute Arbitrary Code and Obtain Potentially Sensitive Information - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.