phpMyAdmin Prior to 3.3.10.2 and 3.4.3.1 Multiple Remote Vulnerabilities
BID:48563
Info
phpMyAdmin Prior to 3.3.10.2 and 3.4.3.1 Multiple Remote Vulnerabilities
| Bugtraq ID: | 48563 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2505 CVE-2011-2506 CVE-2011-2507 CVE-2011-2508 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2011 12:00AM |
| Updated: | Apr 13 2015 10:01PM |
| Credit: | Frans Pehrson of Xxor AB. |
| Vulnerable: |
Typo3 phpMyAdmin 4.11.1 phpMyAdmin phpMyAdmin 3.4.3 phpMyAdmin phpMyAdmin 3.3.8 phpMyAdmin phpMyAdmin 3.3.7 phpMyAdmin phpMyAdmin 3.3.6 phpMyAdmin phpMyAdmin 3.4.1 phpMyAdmin phpMyAdmin 3.3.9.2 phpMyAdmin phpMyAdmin 3.3.8.1 phpMyAdmin phpMyAdmin 3.3.6 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Typo3 phpMyAdmin 4.11.2 phpMyAdmin phpMyAdmin 3.4.3.1 phpMyAdmin phpMyAdmin 3.3.10.2 |
Discussion
phpMyAdmin Prior to 3.3.10.2 and 3.4.3.1 Multiple Remote Vulnerabilities
phpMyAdmin is prone to multiple remote vulnerabilities, including PHP code-execution and local file-include vulnerabilities.
Successful attacks can compromise the affected application and possibly the underlying computer.
phpMyAdmin versions prior to 3.3.10.2 and 3.4.3.1 are vulnerable.
phpMyAdmin is prone to multiple remote vulnerabilities, including PHP code-execution and local file-include vulnerabilities.
Successful attacks can compromise the affected application and possibly the underlying computer.
phpMyAdmin versions prior to 3.3.10.2 and 3.4.3.1 are vulnerable.
Exploit / POC
phpMyAdmin Prior to 3.3.10.2 and 3.4.3.1 Multiple Remote Vulnerabilities
The following exploit and proof-of-concept code is available:
The following exploit and proof-of-concept code is available:
Solution / Fix
phpMyAdmin Prior to 3.3.10.2 and 3.4.3.1 Multiple Remote Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva phpmyadmin-3.4.3.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva phpmyadmin-3.4.3.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
References
phpMyAdmin Prior to 3.3.10.2 and 3.4.3.1 Multiple Remote Vulnerabilities
References:
References:
- phpMyAdmin 3.x Multiple Remote Code Executions (Haxxor Security)
- phpMyAdmin 3.x preg_replace RCE POC (Hazzor Security)
- phpMyAdmin Homepage (phpMyAdmin)
- phpMyAdmin 3.x preg_replace RCE POC (Mango
) - PMASA-2011-5 (phpMyAdmin)
- PMASA-2011-6 (phpMyAdmin)
- PMASA-2011-7 (phpMyAdmin)
- PMASA-2011-8 (phpMyAdmin)
- TYPO3 Security Bulletin TYPO3-SA-2011-008 (TYPO3)