Korean
<< Back
VID 22604
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The version of phpMyAdmin on the remote host is 4.0.x prior to 4.0.4.1. This version is affected by a security vulnerability.

- The application contains a flaw where the 'import.php' script does not properly sanitize input. This could allow attackers to inject arbitrary GLOBALS variables and thereby manipulate any configuration parameter.

* Note: This check solely relied on the version number of the remote phpMyAdmin software to assess this vulnerability, so this might be a false positive.

* References:
http://www.phpmyadmin.net/home_page/security/PMASA-2013-7.php

* Platforms Affected:
phpMyAdmin 4.0.x prior to 4.0.4.1
Any operating system Any version
Recommendation Upgrade to the latest version of phpMyAdmin (4.0.4.1 or later), available from the phpMyAdmin Download Web page at
http://www.phpmyadmin.net/home_page/downloads.php
Related URL CVE-2013-4729 (CVE)
Related URL 60940 (SecurityFocus)
Related URL (ISS)