phpMyAdmin 3.3.x / 3.4.x < 3.3.10.2 / 3.4.3.1 Multiple Vulnerabilities (PMASA-2011-5 - PMASA-2011-8)

high Nessus Plugin ID 57346

Synopsis

The remote web server contains a PHP application that is affected by multiple vulnerabilities.

Description

The remote host contains a version of phpMyAdmin - 3.3.x less than 3.3.10.2 or 3.4.x less than 3.4.3.1 - that is affected by multiple vulnerabilities :

- An error in the file 'libraries/auth/swekey/swekey.auth.lib.php' allows an attacker to modify the 'SESSION' superglobal array.
(CVE-2011-2505)

- An error in the file 'setup/lib/ConfigGenerator.class.php' does not properly handle PHP comment-closing delimiters. This can allow an attacker inject static code via a modified 'SESSION' superglobal array. (CVE-2011-2506)

- An error in the file 'libraries/server_synchronize.lib.php' does not properly call the 'preg_replace' function. This can allow an attacker to execute arbitrary code via a modified 'SESSION' superglobal array. (CVE-2011-2507)

- An local file inclusion error exists in the 'PMA_displayTableBody' function in the file 'libraries/display_tbl.lib.php' that can allow an attacker to obtain sensitive information or execute code in file already present on the host.
(CVE-2011-2508)

Solution

Upgrade to phpMyAdmin version 3.3.10.2 / 3.4.3.1 or later.

See Also

http://ha.xxor.se/2011/07/phpmyadmin-3x-multiple-remote-code.html

http://www.phpmyadmin.net/home_page/security/PMASA-2011-5.php

http://www.phpmyadmin.net/home_page/security/PMASA-2011-6.php

http://www.phpmyadmin.net/home_page/security/PMASA-2011-7.php

http://www.phpmyadmin.net/home_page/security/PMASA-2011-8.php

Plugin Details

Severity: High

ID: 57346

File Name: phpmyadmin_pmasa_2011_8.nasl

Version: 1.10

Type: remote

Family: CGI abuses

Published: 12/20/2011

Updated: 4/11/2022

Configuration: Enable paranoid mode, Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:phpmyadmin:phpmyadmin

Required KB Items: www/phpMyAdmin, www/PHP, Settings/ParanoidReport

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No exploit is required

Patch Publication Date: 7/2/2011

Vulnerability Publication Date: 7/2/2011

Exploitable With

Elliot (Phpmyadmin 3.x RCE)

Reference Information

CVE: CVE-2011-2505, CVE-2011-2506, CVE-2011-2507, CVE-2011-2508

BID: 48563