CVE
- Id
- 50418
- CVE No.
- CVE-2011-2506
- Status
- Candidate
- Description
- setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array.
- Phase
- Assigned (20110615)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
545009 | 50418 | CVE-2011-2506 | BUGTRAQ:20110707 phpMyAdmin 3.x Multiple Remote Code Executions | View |
545010 | 50418 | CVE-2011-2506 | URL:http://www.securityfocus.com/archive/1/archive/1/518804/100/0/threaded | View |
545011 | 50418 | CVE-2011-2506 | EXPLOIT-DB:17514 | View |
545012 | 50418 | CVE-2011-2506 | URL:http://www.exploit-db.com/exploits/17514/ | View |
545013 | 50418 | CVE-2011-2506 | MLIST:[oss-security] 20110628 CVE Request: phpMyAdmin 3.4 Multiple Vulnerabilities | View |
545014 | 50418 | CVE-2011-2506 | URL:http://www.openwall.com/lists/oss-security/2011/06/28/2 | View |
545015 | 50418 | CVE-2011-2506 | MLIST:[oss-security] 20110628 Re: CVE Request: phpMyAdmin 3.4 Multiple Vulnerabilities | View |
545016 | 50418 | CVE-2011-2506 | URL:http://www.openwall.com/lists/oss-security/2011/06/28/6 | View |
545017 | 50418 | CVE-2011-2506 | MLIST:[oss-security] 20110628 Re: [Phpmyadmin-security] CVE Request: phpMyAdmin 3.4 Multiple Vulnerabilities | View |
545018 | 50418 | CVE-2011-2506 | URL:http://www.openwall.com/lists/oss-security/2011/06/28/8 | View |
545019 | 50418 | CVE-2011-2506 | MLIST:[oss-security] 20110629 Re: CVE Request: phpMyAdmin 3.4 Multiple Vulnerabilities | View |
545020 | 50418 | CVE-2011-2506 | URL:http://www.openwall.com/lists/oss-security/2011/06/29/11 | View |
545021 | 50418 | CVE-2011-2506 | MISC:http://ha.xxor.se/2011/07/phpmyadmin-3x-multiple-remote-code.html | View |
545022 | 50418 | CVE-2011-2506 | MISC:http://www.xxor.se/advisories/phpMyAdmin_3.x_Multiple_Remote_Code_Executions.txt | View |
545023 | 50418 | CVE-2011-2506 | CONFIRM:http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commit;h=0fbedaf5fd7a771d0885c6b7385d934fc90d0d7f | View |
545024 | 50418 | CVE-2011-2506 | CONFIRM:http://typo3.org/teams/security/security-bulletins/typo3-sa-2011-008/ | View |
545025 | 50418 | CVE-2011-2506 | CONFIRM:http://www.phpmyadmin.net/home_page/security/PMASA-2011-6.php | View |
545026 | 50418 | CVE-2011-2506 | DEBIAN:DSA-2286 | View |
545027 | 50418 | CVE-2011-2506 | URL:http://www.debian.org/security/2011/dsa-2286 | View |
545028 | 50418 | CVE-2011-2506 | FEDORA:FEDORA-2011-9144 | View |
545029 | 50418 | CVE-2011-2506 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062719.html | View |
545030 | 50418 | CVE-2011-2506 | MANDRIVA:MDVSA-2011:124 | View |
545031 | 50418 | CVE-2011-2506 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2011:124 | View |
545032 | 50418 | CVE-2011-2506 | OSVDB:73612 | View |
545033 | 50418 | CVE-2011-2506 | URL:http://www.osvdb.org/73612 | View |
545034 | 50418 | CVE-2011-2506 | SECUNIA:45139 | View |
545035 | 50418 | CVE-2011-2506 | URL:http://secunia.com/advisories/45139 | View |
545036 | 50418 | CVE-2011-2506 | SECUNIA:45292 | View |
545037 | 50418 | CVE-2011-2506 | URL:http://secunia.com/advisories/45292 | View |
545038 | 50418 | CVE-2011-2506 | SECUNIA:45315 | View |
545039 | 50418 | CVE-2011-2506 | URL:http://secunia.com/advisories/45315 | View |
545040 | 50418 | CVE-2011-2506 | SREASON:8306 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
31886 | JVNDB-2011-002126 | libvirt における整数オーバーフローの脆弱性 | libvirt には、整数オーバーフローの脆弱性が存在します。 | CVE-2011-2511 | 50418 | 4 | http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-002126.html | View |