CVE Vulnerabilities

CVE-2013-4729

Published: Jul 04, 2013 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authenticated users to modify the GLOBALS superglobal array, and consequently change the configuration, via a crafted request.

Affected Software

Name Vendor Start Version End Version
Phpmyadmin Phpmyadmin 4.0.0 (including) 4.0.0 (including)
Phpmyadmin Phpmyadmin 4.0.0-rc2 (including) 4.0.0-rc2 (including)
Phpmyadmin Phpmyadmin 4.0.0-rc3 (including) 4.0.0-rc3 (including)
Phpmyadmin Phpmyadmin 4.0.1 (including) 4.0.1 (including)
Phpmyadmin Phpmyadmin 4.0.2 (including) 4.0.2 (including)
Phpmyadmin Phpmyadmin 4.0.3 (including) 4.0.3 (including)
Phpmyadmin Phpmyadmin 4.0.4 (including) 4.0.4 (including)
Phpmyadmin Ubuntu lucid *
Phpmyadmin Ubuntu precise *
Phpmyadmin Ubuntu quantal *
Phpmyadmin Ubuntu raring *
Phpmyadmin Ubuntu upstream *

References