CVE-2007-1325Phpmyadmin vulnerability

4 documents4 sources
Severity
7.1HIGHNVD
OSV2.1
EPSS
1.0%
top 23.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 7
Latest updateMay 1

Description

The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin.

CVSS vector

AV:N/AC:M/C:N/I:N/A:CExploitability: 8.6 | Impact: 6.9

Affected Packages3 packages

debiandebian/phpmyadmin< phpmyadmin 4:2.10.0.2-1 (bookworm)
Debianphpmyadmin/phpmyadmin< 4:2.10.0.2-1+3
NVDphpmyadmin/phpmyadmin2.10.0.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wxxc-635g-7hm3: The PMA_ArrayWalkRecursive function in libraries/common2022-05-01
OSV
CVE-2007-1325: The PMA_ArrayWalkRecursive function in libraries/common2007-03-07

📋Vendor Advisories

1
Debian
CVE-2007-1325: phpmyadmin - The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin be...2007