Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2011-2506

setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.219
EPSS Ranking 95.5%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2011-2506


Contact Us

Shodan ® - All rights reserved