Vulnerability Description
The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpmyadmin | Phpmyadmin | 2.11.0 |
Related Weaknesses (CWE)
References
- http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba
- http://secunia.com/advisories/41058Vendor Advisory
- http://secunia.com/advisories/41185Vendor Advisory
- http://sourceforge.net/tracker/?func=detail&aid=3045132&group_id=23067&atid=3774Exploit
- http://www.debian.org/security/2010/dsa-2097
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:163
- http://www.phpmyadmin.net/home_page/security/PMASA-2010-4.phpPatchVendor Advisory
- http://www.securityfocus.com/bid/42591Patch
- http://www.vupen.com/english/advisories/2010/2223Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2231Vendor Advisory
- http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba
- http://secunia.com/advisories/41058Vendor Advisory
- http://secunia.com/advisories/41185Vendor Advisory
- http://sourceforge.net/tracker/?func=detail&aid=3045132&group_id=23067&atid=3774Exploit
- http://www.debian.org/security/2010/dsa-2097
FAQ
What is CVE-2010-3055?
CVE-2010-3055 is a vulnerability with a CVSS score of 7.5 (HIGH). The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary...
How severe is CVE-2010-3055?
CVE-2010-3055 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-3055?
Check the references section above for vendor advisories and patch information. Affected products include: Phpmyadmin Phpmyadmin.