phpMyAdmin Superglobal Session Manipulation Arbitrary PHP Code Execution Vulnerability
Publish Date: 21 luglio 2015
Gravità: : Medio
Data notifica: 21 luglio 2015
Descrizione
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."
Informazioni esposizione:
Apply associated Trend Micro DPI Rules.
Soluzioni
Trend Micro Deep Security DPI Rule Number: 1005686