Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:PHP:PHPMYADMIN:VAR-INJECT

Severity

Minor

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

phpMyAdmin session_to_unset session variable injection attempt detected

Release Date

2016/08/26

Update Number

2773

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: phpMyAdmin session_to_unset session variable injection attempt detected


This signature detects attempts to exploit a known vulnerability against phpMyAdmin. A successful attack can lead to arbitrary code execution.

Extended Description

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

Affected Products

  • Phpmyadmin phpmyadmin 3.0.0
  • Phpmyadmin phpmyadmin 3.0.1
  • Phpmyadmin phpmyadmin 3.0.1.1
  • Phpmyadmin phpmyadmin 3.1.0
  • Phpmyadmin phpmyadmin 3.1.1
  • Phpmyadmin phpmyadmin 3.1.2
  • Phpmyadmin phpmyadmin 3.1.3
  • Phpmyadmin phpmyadmin 3.1.3.1
  • Phpmyadmin phpmyadmin 3.1.3.2
  • Phpmyadmin phpmyadmin 3.1.4
  • Phpmyadmin phpmyadmin 3.1.5
  • Phpmyadmin phpmyadmin 3.2.0
  • Phpmyadmin phpmyadmin 3.2.1
  • Phpmyadmin phpmyadmin 3.2.2
  • Phpmyadmin phpmyadmin 3.3.0.0
  • Phpmyadmin phpmyadmin 3.3.1.0
  • Phpmyadmin phpmyadmin 3.3.10.0
  • Phpmyadmin phpmyadmin 3.3.10.1
  • Phpmyadmin phpmyadmin 3.3.2.0
  • Phpmyadmin phpmyadmin 3.3.3.0
  • Phpmyadmin phpmyadmin 3.3.4.0
  • Phpmyadmin phpmyadmin 3.3.5.0
  • Phpmyadmin phpmyadmin 3.3.5.1
  • Phpmyadmin phpmyadmin 3.3.6
  • Phpmyadmin phpmyadmin 3.3.7
  • Phpmyadmin phpmyadmin 3.3.8
  • Phpmyadmin phpmyadmin 3.3.8.1
  • Phpmyadmin phpmyadmin 3.3.9.0
  • Phpmyadmin phpmyadmin 3.3.9.1
  • Phpmyadmin phpmyadmin 3.3.9.2
  • Phpmyadmin phpmyadmin 3.4.0.0
  • Phpmyadmin phpmyadmin 3.4.1.0
  • Phpmyadmin phpmyadmin 3.4.2.0
  • Phpmyadmin phpmyadmin 3.4.3.0

References

  • CVE: CVE-2011-2505
  • CVE: CVE-2011-2506

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out