CVE
- Id
- 48899
- CVE No.
- CVE-2011-0987
- Status
- Candidate
- Description
- The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user"s execution of a SQL query by creating a bookmark.
- Phase
- Assigned (20110211)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
530823 | 48899 | CVE-2011-0987 | CONFIRM:http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commit;h=a5464b4daff0059cdf8c9e5f4d54a80e2dd2a5b0 | View |
530824 | 48899 | CVE-2011-0987 | CONFIRM:http://www.phpmyadmin.net/home_page/security/PMASA-2011-2.php | View |
530825 | 48899 | CVE-2011-0987 | DEBIAN:DSA-2167 | View |
530826 | 48899 | CVE-2011-0987 | URL:http://www.debian.org/security/2011/dsa-2167 | View |
530827 | 48899 | CVE-2011-0987 | FEDORA:FEDORA-2011-1373 | View |
530828 | 48899 | CVE-2011-0987 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054349.html | View |
530829 | 48899 | CVE-2011-0987 | FEDORA:FEDORA-2011-1408 | View |
530830 | 48899 | CVE-2011-0987 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054355.html | View |
530831 | 48899 | CVE-2011-0987 | FEDORA:FEDORA-2011-1282 | View |
530832 | 48899 | CVE-2011-0987 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054525.html | View |
530833 | 48899 | CVE-2011-0987 | MANDRIVA:MDVSA-2011:026 | View |
530834 | 48899 | CVE-2011-0987 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2011:026 | View |
530835 | 48899 | CVE-2011-0987 | BID:46359 | View |
530836 | 48899 | CVE-2011-0987 | URL:http://www.securityfocus.com/bid/46359 | View |
530837 | 48899 | CVE-2011-0987 | SECUNIA:43324 | View |
530838 | 48899 | CVE-2011-0987 | URL:http://secunia.com/advisories/43324 | View |
530839 | 48899 | CVE-2011-0987 | SECUNIA:43391 | View |
530840 | 48899 | CVE-2011-0987 | URL:http://secunia.com/advisories/43391 | View |
530841 | 48899 | CVE-2011-0987 | SECUNIA:43478 | View |
530842 | 48899 | CVE-2011-0987 | URL:http://secunia.com/advisories/43478 | View |
530843 | 48899 | CVE-2011-0987 | VUPEN:ADV-2011-0381 | View |
530844 | 48899 | CVE-2011-0987 | URL:http://www.vupen.com/english/advisories/2011/0381 | View |
530845 | 48899 | CVE-2011-0987 | VUPEN:ADV-2011-0385 | View |
530846 | 48899 | CVE-2011-0987 | URL:http://www.vupen.com/english/advisories/2011/0385 | View |
530847 | 48899 | CVE-2011-0987 | VUPEN:ADV-2011-0409 | View |
530848 | 48899 | CVE-2011-0987 | URL:http://www.vupen.com/english/advisories/2011/0409 | View |
530849 | 48899 | CVE-2011-0987 | VUPEN:ADV-2011-0512 | View |
530850 | 48899 | CVE-2011-0987 | URL:http://www.vupen.com/english/advisories/2011/0512 | View |
530851 | 48899 | CVE-2011-0987 | VUPEN:ADV-2011-0570 | View |
530852 | 48899 | CVE-2011-0987 | URL:http://www.vupen.com/english/advisories/2011/0570 | View |
530853 | 48899 | CVE-2011-0987 | XF:phpmyadmin-bookmark-security-bypass(65390) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
34043 | JVNDB-2011-004285 | Mono におけるサービス運用妨害 (DoS) の脆弱性 | Monoには、Moonlight が使用される際、再起動した MonoThread インスタンス内のメンバデータに関する処理に不備があるため、サービス運用妨害 (プラグインクラッシュ) 状態となる、または重要な情報を取得される脆弱性が存在します。 | CVE-2011-0992 | 48899 | 5.8 | http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-004285.html | View |