cvelist/2011/2xxx/CVE-2011-2506.json
2018-10-09 15:05:48 -04:00

153 lines
5.4 KiB
JSON

{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2011-2506",
"STATE" : "PUBLIC"
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a",
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
},
"vendor_name" : "n/a"
}
]
}
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array."
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "n/a"
}
]
}
]
},
"references" : {
"reference_data" : [
{
"name" : "20110707 phpMyAdmin 3.x Multiple Remote Code Executions",
"refsource" : "BUGTRAQ",
"url" : "http://www.securityfocus.com/archive/1/518804/100/0/threaded"
},
{
"name" : "17514",
"refsource" : "EXPLOIT-DB",
"url" : "http://www.exploit-db.com/exploits/17514/"
},
{
"name" : "[oss-security] 20110628 CVE Request: phpMyAdmin 3.4 Multiple Vulnerabilities",
"refsource" : "MLIST",
"url" : "http://www.openwall.com/lists/oss-security/2011/06/28/2"
},
{
"name" : "[oss-security] 20110628 Re: CVE Request: phpMyAdmin 3.4 Multiple Vulnerabilities",
"refsource" : "MLIST",
"url" : "http://www.openwall.com/lists/oss-security/2011/06/28/6"
},
{
"name" : "[oss-security] 20110628 Re: [Phpmyadmin-security] CVE Request: phpMyAdmin 3.4 Multiple Vulnerabilities",
"refsource" : "MLIST",
"url" : "http://www.openwall.com/lists/oss-security/2011/06/28/8"
},
{
"name" : "[oss-security] 20110629 Re: CVE Request: phpMyAdmin 3.4 Multiple Vulnerabilities",
"refsource" : "MLIST",
"url" : "http://www.openwall.com/lists/oss-security/2011/06/29/11"
},
{
"name" : "http://ha.xxor.se/2011/07/phpmyadmin-3x-multiple-remote-code.html",
"refsource" : "MISC",
"url" : "http://ha.xxor.se/2011/07/phpmyadmin-3x-multiple-remote-code.html"
},
{
"name" : "http://www.xxor.se/advisories/phpMyAdmin_3.x_Multiple_Remote_Code_Executions.txt",
"refsource" : "MISC",
"url" : "http://www.xxor.se/advisories/phpMyAdmin_3.x_Multiple_Remote_Code_Executions.txt"
},
{
"name" : "http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commit;h=0fbedaf5fd7a771d0885c6b7385d934fc90d0d7f",
"refsource" : "CONFIRM",
"url" : "http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commit;h=0fbedaf5fd7a771d0885c6b7385d934fc90d0d7f"
},
{
"name" : "http://typo3.org/teams/security/security-bulletins/typo3-sa-2011-008/",
"refsource" : "CONFIRM",
"url" : "http://typo3.org/teams/security/security-bulletins/typo3-sa-2011-008/"
},
{
"name" : "http://www.phpmyadmin.net/home_page/security/PMASA-2011-6.php",
"refsource" : "CONFIRM",
"url" : "http://www.phpmyadmin.net/home_page/security/PMASA-2011-6.php"
},
{
"name" : "DSA-2286",
"refsource" : "DEBIAN",
"url" : "http://www.debian.org/security/2011/dsa-2286"
},
{
"name" : "FEDORA-2011-9144",
"refsource" : "FEDORA",
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062719.html"
},
{
"name" : "MDVSA-2011:124",
"refsource" : "MANDRIVA",
"url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2011:124"
},
{
"name" : "73612",
"refsource" : "OSVDB",
"url" : "http://www.osvdb.org/73612"
},
{
"name" : "45139",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/45139"
},
{
"name" : "45292",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/45292"
},
{
"name" : "45315",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/45315"
},
{
"name" : "8306",
"refsource" : "SREASON",
"url" : "http://securityreason.com/securityalert/8306"
}
]
}
}