CVE Database
/

CVE-2007-1325

Back to search

CVE-2007-1325

Published: Mar 7, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin.

VendorProductVersions

n/a

n/a

affected
n/a

References

26733
third-party-advisory
x_refsource_SECUNIA
22841
vdb-entry
x_refsource_BID
DSA-1370
vendor-advisory
x_refsource_DEBIAN
MDKSA-2007:199
vendor-advisory
x_refsource_MANDRIVA
36834
vdb-entry
x_refsource_OSVDB
ADV-2007-0831
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now