CVE-2011-2719Improper Input Validation in Phpmyadmin

Severity
6.4MEDIUMNVD
EPSS
1.9%
top 16.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 1
Latest updateMay 14

Description

libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated with Swekey authentication, which allows remote attackers to modify the SESSION superglobal array, other superglobal arrays, and certain swekey.auth.lib.php local variables via a crafted query string, a related issue to CVE-2011-2505.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages3 packages

debiandebian/phpmyadmin< phpmyadmin 4:3.4.3.2-1 (bookworm)
Debianphpmyadmin/phpmyadmin< 4:3.4.3.2-1+3
NVDphpmyadmin/phpmyadmin36 versions+35

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fmmw-6q24-3wqx: libraries/auth/swekey/swekey2022-05-14
OSV
CVE-2011-2719: libraries/auth/swekey/swekey2011-08-01

📋Vendor Advisories

1
Debian
CVE-2011-2719: phpmyadmin - libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and ...2011

💬Community

1
Bugzilla
CVE-2011-2719 phpMyAdmin: v3.3.10.3, v3.4.3.2: Possible session manipulation in Swekey extention authentication (PMASA-2011-12)2011-07-25