CVE-2011-2643
published 2011-08-01CVE-2011-2643: Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and…
PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.32%
87.3th percentile
Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:3.4.3.2-1 (bookworm) | phpmyadmin 4:3.4.3.2-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.3.2-1 | 4:3.4.3.2-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.3.2-1 | 4:3.4.3.2-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.3.2-1 | 4:3.4.3.2-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.3.2-1 | 4:3.4.3.2-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x95j-5m75-mq26: Directory traversal vulnerability in sql
ghsa_unreviewed·2022-05-17
CVE-2011-2643 [MEDIUM] CWE-22 GHSA-x95j-5m75-mq26: Directory traversal vulnerability in sql
Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.
OSV
CVE-2011-2643: Directory traversal vulnerability in sql
osv·2011-08-01·CVSS 6.8
CVE-2011-2643 [MEDIUM] CVE-2011-2643: Directory traversal vulnerability in sql
Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.
Debian
CVE-2011-2643: phpmyadmin - Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2,...
vendor_debian·2011·CVSS 6.8
CVE-2011-2643 [MEDIUM] CVE-2011-2643: phpmyadmin - Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2,...
Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.
Scope: local
bookworm: resolved (fixed in 4:3.4.3.2-1)
bullseye: resolved (fixed in 4:3.4.3.2-1)
forky: resolved (fixed in 4:3.4.3.2-1)
sid: resolved (fixed in 4:3.4.3.2-1)
trixie: resolved (fixed in 4:3.4.3.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2643 phpMyAdmin: v3.3.10.3, v3.4.3.2: Local file inclusion via a crafted MIME-type transformation parameter (PMASA-2011-10)
bugzilla·2011-07-25·CVSS 6.8
CVE-2011-2643 [MEDIUM] CVE-2011-2643 phpMyAdmin: v3.3.10.3, v3.4.3.2: Local file inclusion via a crafted MIME-type transformation parameter (PMASA-2011-10)
CVE-2011-2643 phpMyAdmin: v3.3.10.3, v3.4.3.2: Local file inclusion via a crafted MIME-type transformation parameter (PMASA-2011-10)
A local file inclusion flaw was found in the way phpMyAdmin, the MySQL over WWW administration tool, performed particular SQL query execution. A local attacker could use this flaw to obtain sensitive information via specially-crafted MIME-type transformation parameter.
References:
[1] http://www.phpmyadmin.net/home_page/security/PMASA-2011-10.php
[2] http://www.phpmyadmin.net/home_page/news.php
Upstream patches:
[3] http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commitdiff;h=f63e1bb42a37401b2fdfcd2e66cce92b7ea2025c
Versions affected:
Versions 3.4.0 to 3.4.3.1 are affected.
Further flaw exploitation details:
The phpMyAdmin'
Bugzilla
CVE-2011-2643 phpMyAdmin various flaws [epel-6]
bugzilla·2011-07-25·CVSS 6.8
CVE-2011-2643 [MEDIUM] CVE-2011-2643 phpMyAdmin various flaws [epel-6]
CVE-2011-2643 phpMyAdmin various flaws [epel-6]
epel-6 tracking bug for phpMyAdmin: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug PMASA-2011-11
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=725382,725383
---
Adding parent bug PMASA-2011-12
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=725382,725383,725384
---
phpMyAdmin-3.4.3.2-1.fc15 has been submitted as an update for Fedora 15.
https://admin.fedoraproject.org/updates/phpMyAdmin-3.4.3.2-1.fc15
---
phpMyAdmin-3.4.3.2-1.fc14 has been submitted as an update f
Bugzilla
CVE-2011-2642 CVE-2011-2643 phpMyAdmin various flaws [fedora-all]
bugzilla·2011-07-25·CVSS 2.6
CVE-2011-2642 [LOW] CVE-2011-2642 CVE-2011-2643 phpMyAdmin various flaws [fedora-all]
CVE-2011-2642 CVE-2011-2643 phpMyAdmin various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=725381
Please note: this issue affects multiple supporte
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063410.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-August/063418.htmlhttp://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commit%3Bh=f63e1bb42a37401b2fdfcd2e66cce92b7ea2025chttp://secunia.com/advisories/45365http://secunia.com/advisories/45515http://www.mandriva.com/security/advisories?name=MDVSA-2011:124http://www.phpmyadmin.net/home_page/security/PMASA-2011-10.phphttp://www.securityfocus.com/bid/48874https://bugzilla.redhat.com/show_bug.cgi?id=725382https://exchange.xforce.ibmcloud.com/vulnerabilities/68767http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063410.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-August/063418.htmlhttp://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commit%3Bh=f63e1bb42a37401b2fdfcd2e66cce92b7ea2025chttp://secunia.com/advisories/45365http://secunia.com/advisories/45515http://www.mandriva.com/security/advisories?name=MDVSA-2011:124http://www.phpmyadmin.net/home_page/security/PMASA-2011-10.phphttp://www.securityfocus.com/bid/48874https://bugzilla.redhat.com/show_bug.cgi?id=725382https://exchange.xforce.ibmcloud.com/vulnerabilities/68767
2011-08-01
Published