CVE-2011-2505
CVE-2011-2505
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."
Produtos afetados
n/a · n/aPoCs públicas encontradas — 3
cve_referencewww.exploit-db.com/exploits/17514/não verificadoexploitdbwww.exploit-db.com/exploits/17514não verificadoexploitdbwww.exploit-db.com/exploits/17510não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://ha.xxor.se/2011/07/phpmyadmin-3x-multiple-remote-code.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062719.htmlhttp://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commit%3Bh=7ebd958b2bf59f96fecd5b3322bdbd0b244a7967http://secunia.com/advisories/45139http://secunia.com/advisories/45292http://secunia.com/advisories/45315http://securityreason.com/securityalert/8306http://typo3.org/teams/security/security-bulletins/typo3-sa-2011-008/http://www.debian.org/security/2011/dsa-2286http://www.exploit-db.com/exploits/17514/http://www.mandriva.com/security/advisories?name=MDVSA-2011:124http://www.openwall.com/lists/oss-security/2011/06/28/2