phpMyAdmin 'import.php' Security Vulnerability
BID:60940
Info
phpMyAdmin 'import.php' Security Vulnerability
| Bugtraq ID: | 60940 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4729 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2013 12:00AM |
| Updated: | Jun 30 2013 12:00AM |
| Credit: | Markus Wulftange of Daimler TSS |
| Vulnerable: |
phpMyAdmin phpMyAdmin 4.0.4 phpMyAdmin phpMyAdmin 4.0.3 phpMyAdmin phpMyAdmin 4.0.2 phpMyAdmin phpMyAdmin 4.0.1 phpMyAdmin phpMyAdmin 4.0 |
| Not Vulnerable: |
phpMyAdmin phpMyAdmin 4.0.4.1 |
Discussion
phpMyAdmin 'import.php' Security Vulnerability
phpMyAdmin is prone to a remote security vulnerability.
Attackers can exploit this issue to inject arbitrary GLOBALS variables and manipulate any configuration parameters.
phpMyAdmin 4.0.0 through 4.0.4 are vulnerable.
phpMyAdmin is prone to a remote security vulnerability.
Attackers can exploit this issue to inject arbitrary GLOBALS variables and manipulate any configuration parameters.
phpMyAdmin 4.0.0 through 4.0.4 are vulnerable.
Exploit / POC
phpMyAdmin 'import.php' Security Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
phpMyAdmin 'import.php' Security Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
phpMyAdmin 'import.php' Security Vulnerability
References:
References:
- [security] Global variables scope injection vulnerability (phpmyadmin)
- phpMyAdmin Homepage (phpMyAdmin)
- PMASA-2013-7 (phpMyAdmin)