CVE-2011-2505

critical

Description

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

References

https://github.com/advisories/GHSA-vqcm-r62w-w437

https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5408

http://www.xxor.se/advisories/phpMyAdmin_3.x_Multiple_Remote_Code_Executions.txt

http://www.securityfocus.com/archive/1/518804/100/0/threaded

http://www.phpmyadmin.net/home_page/security/PMASA-2011-5.php

http://www.osvdb.org/73611

http://www.openwall.com/lists/oss-security/2011/06/29/11

http://www.openwall.com/lists/oss-security/2011/06/28/8

http://www.openwall.com/lists/oss-security/2011/06/28/6

http://www.openwall.com/lists/oss-security/2011/06/28/2

http://www.mandriva.com/security/advisories?name=MDVSA-2011:124

http://www.exploit-db.com/exploits/17514/

http://www.debian.org/security/2011/dsa-2286

http://typo3.org/teams/security/security-bulletins/typo3-sa-2011-008/

http://securityreason.com/securityalert/8306

http://secunia.com/advisories/45315

http://secunia.com/advisories/45292

http://secunia.com/advisories/45139

http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commit%3Bh=7ebd958b2bf59f96fecd5b3322bdbd0b244a7967

http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062719.html

http://ha.xxor.se/2011/07/phpmyadmin-3x-multiple-remote-code.html

Details

Source: Mitre, NVD

Published: 2011-07-14

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical

EPSS

EPSS: 0.12879