CVE Database
/

CVE-2011-2507

Back to search

CVE-2011-2507

Published: Jul 14, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION superglobal array.

VendorProductVersions

n/a

n/a

affected
n/a

References

45292
third-party-advisory
x_refsource_SECUNIA
MDVSA-2011:124
vendor-advisory
x_refsource_MANDRIVA
8306
third-party-advisory
x_refsource_SREASON
45139
third-party-advisory
x_refsource_SECUNIA
DSA-2286
vendor-advisory
x_refsource_DEBIAN
73613
vdb-entry
x_refsource_OSVDB
45315
third-party-advisory
x_refsource_SECUNIA
FEDORA-2011-9144
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now