CVE-2011-2505

EUVD-2022-5408
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
phpmyadminphpmyadmin
3.0.0
phpmyadminphpmyadmin
3.0.0:alpha
phpmyadminphpmyadmin
3.0.0:beta
phpmyadminphpmyadmin
3.0.0:rc1
phpmyadminphpmyadmin
3.0.1
phpmyadminphpmyadmin
3.0.1:rc1
phpmyadminphpmyadmin
3.0.1.1
phpmyadminphpmyadmin
3.1.0
phpmyadminphpmyadmin
3.1.0:beta1
phpmyadminphpmyadmin
3.1.1
phpmyadminphpmyadmin
3.1.1:rc1
phpmyadminphpmyadmin
3.1.2
phpmyadminphpmyadmin
3.1.2:rc1
phpmyadminphpmyadmin
3.1.3
phpmyadminphpmyadmin
3.1.3:rc1
phpmyadminphpmyadmin
3.1.3.1
phpmyadminphpmyadmin
3.1.3.2
phpmyadminphpmyadmin
3.1.4
phpmyadminphpmyadmin
3.1.4:rc2
phpmyadminphpmyadmin
3.1.5
phpmyadminphpmyadmin
3.1.5:rc1
phpmyadminphpmyadmin
3.2.0
phpmyadminphpmyadmin
3.2.0:beta1
phpmyadminphpmyadmin
3.2.0:rc1
phpmyadminphpmyadmin
3.2.1
phpmyadminphpmyadmin
3.2.1:rc1
phpmyadminphpmyadmin
3.2.2
phpmyadminphpmyadmin
3.2.2:rc1
phpmyadminphpmyadmin
3.3.0.0
phpmyadminphpmyadmin
3.3.1.0
phpmyadminphpmyadmin
3.3.2.0
phpmyadminphpmyadmin
3.3.3.0
phpmyadminphpmyadmin
3.3.4.0
phpmyadminphpmyadmin
3.3.5.0
phpmyadminphpmyadmin
3.3.5.1
phpmyadminphpmyadmin
3.3.6
phpmyadminphpmyadmin
3.3.7
phpmyadminphpmyadmin
3.3.8
phpmyadminphpmyadmin
3.3.8.1
phpmyadminphpmyadmin
3.3.9.0
phpmyadminphpmyadmin
3.3.9.1
phpmyadminphpmyadmin
3.3.9.2
phpmyadminphpmyadmin
3.3.10.0
phpmyadminphpmyadmin
3.3.10.1
phpmyadminphpmyadmin
3.4.0.0
phpmyadminphpmyadmin
3.4.1.0
phpmyadminphpmyadmin
3.4.2.0
phpmyadminphpmyadmin
3.4.3.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
phpmyadmin
bookworm
4:5.2.1+dfsg-1
fixed
bullseye
4:5.0.4+dfsg2-2+deb11u1
fixed
lenny
not-affected
sid
4:5.2.1+dfsg-4
fixed
trixie
4:5.2.1+dfsg-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
phpmyadmin
hardy
ignored
lucid
ignored
maverick
ignored
natty
ignored
oneiric
Fixed 4:3.4.3.1-1
released
precise
Fixed 4:3.4.3.1-1
released
quantal
Fixed 4:3.4.3.1-1
released
raring
Fixed 4:3.4.3.1-1
released
saucy
Fixed 4:3.4.3.1-1
released
References