Vulnerability Name: | CVE-2013-3240 (CCN-83792) | ||||||||||||||||
Assigned: | 2013-04-24 | ||||||||||||||||
Published: | 2013-04-24 | ||||||||||||||||
Updated: | 2013-11-19 | ||||||||||||||||
Summary: | Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated users to read arbitrary files or possibly have unspecified other impact via a parameter that specifies a crafted export type. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P) 4.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-22 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: BUGTRAQ Type: UNKNOWN 20130424 [waraxe-2013-SA#103] - Multiple Vulnerabilities in phpMyAdmin Source: MITRE Type: CNA CVE-2013-3240 Source: CCN Type: Full-disclosure Mailing List, Wed, 24 Apr 2013 13:41:16 -0700 (PDT) Multiple Vulnerabilities in phpMyAdmin Source: CCN Type: phpMyAdmin Web Site phpMyAdmin Source: CCN Type: PMASA-2013-4 Local file inclusion vulnerability Source: CONFIRM Type: UNKNOWN http://www.phpmyadmin.net/home_page/security/PMASA-2013-4.php Source: CCN Type: BID-59462 phpMyAdmin 'what' Parameter Local File Include Vulnerability Source: XF Type: UNKNOWN phpmyadmin-cve20133240-file-include(83792) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |