cbcvebase.
CVE-2007-1325
published 2007-03-07

CVE-2007-1325: The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which…

PriorityP421high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
1.71%
74.9th percentile
The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianphpmyadmin< phpmyadmin 4:2.10.0.2-1 (bookworm)phpmyadmin 4:2.10.0.2-1 (bookworm)
phpmyadminphpmyadmin<= 2.10.0.1
phpmyadminphpmyadmin>= 0 < 4:2.10.0.2-14:2.10.0.2-1
phpmyadminphpmyadmin>= 0 < 4:2.10.0.2-14:2.10.0.2-1
phpmyadminphpmyadmin>= 0 < 4:2.10.0.2-14:2.10.0.2-1
phpmyadminphpmyadmin>= 0 < 4:2.10.0.2-14:2.10.0.2-1

CVSS provenance

nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv2.1LOW
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.