Vulnerability Name: | CVE-2013-3241 (CCN-83794) | ||||||||||||||||
Assigned: | 2013-04-24 | ||||||||||||||||
Published: | 2013-04-24 | ||||||||||||||||
Updated: | 2013-11-19 | ||||||||||||||||
Summary: | export.php (aka the export script) in phpMyAdmin 4.x before 4.0.0-rc3 overwrites global variables on the basis of the contents of the POST superglobal array, which allows remote authenticated users to inject values via a crafted request. | ||||||||||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N) 3.1 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C)
3.1 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||
References: | Source: BUGTRAQ Type: UNKNOWN 20130424 [waraxe-2013-SA#103] - Multiple Vulnerabilities in phpMyAdmin Source: MITRE Type: CNA CVE-2013-3241 Source: CCN Type: Full-disclosure Mailing List, Wed, 24 Apr 2013 13:41:16 -0700 (PDT) Multiple Vulnerabilities in phpMyAdmin Source: CCN Type: phpMyAdmin Web Site phpMyAdmin Source: CCN Type: PMASA-2013-5 Global variables overwrite in "export.php". Source: CONFIRM Type: Vendor Advisory http://www.phpmyadmin.net/home_page/security/PMASA-2013-5.php Source: CCN Type: BID-59461 phpMyAdmin '$GLOBALS' Array Unauthorized Access Vulnerability Source: XF Type: UNKNOWN phpmyadmin-cve20133241-unauth-access(83794) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-3241 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |