Lucene search

K
cve[email protected]CVE-2008-4096
HistorySep 18, 2008 - 3:04 p.m.

CVE-2008-4096

2008-09-1815:04:27
CWE-20
web.nvd.nist.gov
59
phpmyadmin
code execution
remote authentication
security vulnerability

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

6.1

Confidence

High

EPSS

0.078

Percentile

94.2%

libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.

Affected configurations

NVD
Node
phpmyadminphpmyadminRange2.11.9
OR
phpmyadminphpmyadminMatch2.0
OR
phpmyadminphpmyadminMatch2.0.0
OR
phpmyadminphpmyadminMatch2.0.1
OR
phpmyadminphpmyadminMatch2.0.2
OR
phpmyadminphpmyadminMatch2.0.3
OR
phpmyadminphpmyadminMatch2.0.4
OR
phpmyadminphpmyadminMatch2.0.5
OR
phpmyadminphpmyadminMatch2.1
OR
phpmyadminphpmyadminMatch2.1.0
OR
phpmyadminphpmyadminMatch2.1.1
OR
phpmyadminphpmyadminMatch2.1.2
OR
phpmyadminphpmyadminMatch2.10.0
OR
phpmyadminphpmyadminMatch2.10.0.0
OR
phpmyadminphpmyadminMatch2.10.0.1
OR
phpmyadminphpmyadminMatch2.10.0.2
OR
phpmyadminphpmyadminMatch2.10.1
OR
phpmyadminphpmyadminMatch2.10.01
OR
phpmyadminphpmyadminMatch2.10.1.0
OR
phpmyadminphpmyadminMatch2.10.2
OR
phpmyadminphpmyadminMatch2.10.2.0
OR
phpmyadminphpmyadminMatch2.10.3
OR
phpmyadminphpmyadminMatch2.10.3.0
OR
phpmyadminphpmyadminMatch2.10.3rc1
OR
phpmyadminphpmyadminMatch2.11.0
OR
phpmyadminphpmyadminMatch2.11.0.0
OR
phpmyadminphpmyadminMatch2.11.0beta1
OR
phpmyadminphpmyadminMatch2.11.0rc1
OR
phpmyadminphpmyadminMatch2.11.1
OR
phpmyadminphpmyadminMatch2.11.1.0
OR
phpmyadminphpmyadminMatch2.11.1.1
OR
phpmyadminphpmyadminMatch2.11.1.2
OR
phpmyadminphpmyadminMatch2.11.1rc1
OR
phpmyadminphpmyadminMatch2.11.2
OR
phpmyadminphpmyadminMatch2.11.2.0
OR
phpmyadminphpmyadminMatch2.11.2.1
OR
phpmyadminphpmyadminMatch2.11.2.2
OR
phpmyadminphpmyadminMatch2.11.3
OR
phpmyadminphpmyadminMatch2.11.3.0
OR
phpmyadminphpmyadminMatch2.11.3rc1
OR
phpmyadminphpmyadminMatch2.11.4
OR
phpmyadminphpmyadminMatch2.11.4.0
OR
phpmyadminphpmyadminMatch2.11.4rc1
OR
phpmyadminphpmyadminMatch2.11.5
OR
phpmyadminphpmyadminMatch2.11.5.0
OR
phpmyadminphpmyadminMatch2.11.5.1
OR
phpmyadminphpmyadminMatch2.11.5.2
OR
phpmyadminphpmyadminMatch2.11.5rc1
OR
phpmyadminphpmyadminMatch2.11.6
OR
phpmyadminphpmyadminMatch2.11.6rc1
OR
phpmyadminphpmyadminMatch2.11.7
OR
phpmyadminphpmyadminMatch2.11.8
VendorProductVersionCPE
phpmyadminphpmyadmin2.11.1.2cpe:/a:phpmyadmin:phpmyadmin:2.11.1.2:::
phpmyadminphpmyadmin2.11.5rc1cpe:/a:phpmyadmin:phpmyadmin:2.11.5rc1:::
phpmyadminphpmyadmin2.11.7cpe:/a:phpmyadmin:phpmyadmin:2.11.7:::
phpmyadminphpmyadmin2.10.0.0cpe:/a:phpmyadmin:phpmyadmin:2.10.0.0:::
phpmyadminphpmyadmin2.11.0beta1cpe:/a:phpmyadmin:phpmyadmin:2.11.0beta1:::
phpmyadminphpmyadmin2.11.1rc1cpe:/a:phpmyadmin:phpmyadmin:2.11.1rc1:::
phpmyadminphpmyadmin2.11.2.1cpe:/a:phpmyadmin:phpmyadmin:2.11.2.1:::
phpmyadminphpmyadmin2.11.3cpe:/a:phpmyadmin:phpmyadmin:2.11.3:::
phpmyadminphpmyadmin2.10.0.1cpe:/a:phpmyadmin:phpmyadmin:2.10.0.1:::
phpmyadminphpmyadmin2.11.2.2cpe:/a:phpmyadmin:phpmyadmin:2.11.2.2:::
Rows per page:
1-10 of 521

References

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

6.1

Confidence

High

EPSS

0.078

Percentile

94.2%