CVE-2013-3238

phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a preg_replace function call within the "Replace table prefix" feature.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
phpmyadminphpmyadmin
3.5.0.0
phpmyadminphpmyadmin
3.5.1.0
phpmyadminphpmyadmin
3.5.2.0
phpmyadminphpmyadmin
3.5.2.1
phpmyadminphpmyadmin
3.5.2.2
phpmyadminphpmyadmin
3.5.3.0
phpmyadminphpmyadmin
3.5.4
phpmyadminphpmyadmin
3.5.5
phpmyadminphpmyadmin
3.5.6
phpmyadminphpmyadmin
3.5.7
phpmyadminphpmyadmin
3.5.7:rc1
phpmyadminphpmyadmin
3.5.8:rc1
phpmyadminphpmyadmin
4.0.0:rc2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
phpmyadmin
bullseye
4:5.0.4+dfsg2-2+deb11u1
fixed
bookworm
4:5.2.1+dfsg-1
fixed
sid
4:5.2.1+dfsg-4
fixed
trixie
4:5.2.1+dfsg-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
phpmyadmin
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
lucid
not-affected
hardy
ignored
References