phpMyAdmin '$_SESSION' Array Unauthorized Access Vulnerability
BID:48480
Info
phpMyAdmin '$_SESSION' Array Unauthorized Access Vulnerability
| Bugtraq ID: | 48480 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2011 12:00AM |
| Updated: | Jun 28 2011 12:00AM |
| Credit: | Mango |
| Vulnerable: |
phpMyAdmin phpMyAdmin 3.4.0 |
| Not Vulnerable: | |
Discussion
phpMyAdmin '$_SESSION' Array Unauthorized Access Vulnerability
phpMyAdmin is prone to an unauthorized-access vulnerability.
An attacker can exploit this issue to overwrite variables in the global $_SESSION array with arbitrary data. This may aid in further attacks.
phpMyAdmin 3.4.0 is vulnerable; other versions may also be affected.
phpMyAdmin is prone to an unauthorized-access vulnerability.
An attacker can exploit this issue to overwrite variables in the global $_SESSION array with arbitrary data. This may aid in further attacks.
phpMyAdmin 3.4.0 is vulnerable; other versions may also be affected.
Exploit / POC
phpMyAdmin '$_SESSION' Array Unauthorized Access Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
phpMyAdmin '$_SESSION' Array Unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
phpMyAdmin '$_SESSION' Array Unauthorized Access Vulnerability
References:
References:
- CVE Request: phpMyAdmin 3.4 Multiple Vulnerabilities (Mango )
- phpMyAdmin Homepage (phpMyAdmin)