CVE Vulnerabilities

CVE-2010-3055

Published: Aug 24, 2010 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.

Affected Software

Name Vendor Start Version End Version
Phpmyadmin Phpmyadmin 2.11.0 (including) 2.11.0 (including)
Phpmyadmin Phpmyadmin 2.11.1.0 (including) 2.11.1.0 (including)
Phpmyadmin Phpmyadmin 2.11.1.1 (including) 2.11.1.1 (including)
Phpmyadmin Phpmyadmin 2.11.1.2 (including) 2.11.1.2 (including)
Phpmyadmin Phpmyadmin 2.11.2.0 (including) 2.11.2.0 (including)
Phpmyadmin Phpmyadmin 2.11.2.1 (including) 2.11.2.1 (including)
Phpmyadmin Phpmyadmin 2.11.2.2 (including) 2.11.2.2 (including)
Phpmyadmin Phpmyadmin 2.11.3.0 (including) 2.11.3.0 (including)
Phpmyadmin Phpmyadmin 2.11.4.0 (including) 2.11.4.0 (including)
Phpmyadmin Phpmyadmin 2.11.5.0 (including) 2.11.5.0 (including)
Phpmyadmin Phpmyadmin 2.11.5.1 (including) 2.11.5.1 (including)
Phpmyadmin Phpmyadmin 2.11.5.2 (including) 2.11.5.2 (including)
Phpmyadmin Phpmyadmin 2.11.6.0 (including) 2.11.6.0 (including)
Phpmyadmin Phpmyadmin 2.11.7.0 (including) 2.11.7.0 (including)
Phpmyadmin Phpmyadmin 2.11.7.1 (including) 2.11.7.1 (including)
Phpmyadmin Phpmyadmin 2.11.8.0 (including) 2.11.8.0 (including)
Phpmyadmin Phpmyadmin 2.11.9.0 (including) 2.11.9.0 (including)
Phpmyadmin Phpmyadmin 2.11.9.1 (including) 2.11.9.1 (including)
Phpmyadmin Phpmyadmin 2.11.9.2 (including) 2.11.9.2 (including)
Phpmyadmin Phpmyadmin 2.11.9.3 (including) 2.11.9.3 (including)
Phpmyadmin Phpmyadmin 2.11.9.4 (including) 2.11.9.4 (including)
Phpmyadmin Phpmyadmin 2.11.9.5 (including) 2.11.9.5 (including)
Phpmyadmin Phpmyadmin 2.11.9.6 (including) 2.11.9.6 (including)
Phpmyadmin Phpmyadmin 2.11.10.0 (including) 2.11.10.0 (including)

References