CVE-2013-3238: Medium severity phpMyAdmin phpMyAdmin vulnerability
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a pregreplace function call within the "Replace table prefix" feature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3238?
CVE-2013-3238 is considered a high severity vulnerability due to its potential to allow remote authenticated users to execute arbitrary code.
How do I fix CVE-2013-3238?
To fix CVE-2013-3238, upgrade phpMyAdmin to version 3.5.8 or later for the 3.5.x series or to 4.0.0-rc3 or later for the 4.x series.
What versions of phpMyAdmin are affected by CVE-2013-3238?
CVE-2013-3238 affects phpMyAdmin versions 3.5.0.0 through 3.5.7, as well as specific versions of 4.x before 4.0.0-rc3.
Can CVE-2013-3238 be exploited without authentication?
No, CVE-2013-3238 requires authentication, meaning an attacker must have valid credentials to exploit this vulnerability.
What is the impact of CVE-2013-3238?
The impact of CVE-2013-3238 is that it allows remote authenticated users to execute arbitrary code, potentially compromising the security of the database server.