CVE-2013-4729: Medium severity phpmyadmin vulnerability
Published Jul 4, 2013
·Updated
import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authenticated users to modify the GLOBALS superglobal array, and consequently change the configuration, via a crafted request.
Affected Software
8 affected componentsFixes available
composer/phpmyadmin/phpmyadmin>=4.0<4.0.4.1
4.0.4.1
phpMyAdmin phpMyAdmin=4.0.0
phpMyAdmin phpMyAdmin=4.0.0-rc2
phpMyAdmin phpMyAdmin=4.0.0-rc3
phpMyAdmin phpMyAdmin=4.0.1
phpMyAdmin phpMyAdmin=4.0.2
phpMyAdmin phpMyAdmin=4.0.3
phpMyAdmin phpMyAdmin=4.0.4
Remediation
Event History
Jul 4, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
May 17, 2022
Advisory Published
05:07 AM
Frequently Asked Questions
1
What is the severity of CVE-2013-4729?
CVE-2013-4729 has a medium severity level due to its potential for unauthorized configuration changes.
2
How do I fix CVE-2013-4729?
To fix CVE-2013-4729, upgrade phpMyAdmin to version 4.0.4.1 or later.
3
Who is affected by CVE-2013-4729?
Users of phpMyAdmin versions 4.0.0 through 4.0.4 are affected by CVE-2013-4729.
4
What is the impact of CVE-2013-4729 on phpMyAdmin?
CVE-2013-4729 allows remote authenticated users to manipulate the GLOBALS superglobal array and change configurations.
5
Is CVE-2013-4729 exploitable remotely?
Yes, CVE-2013-4729 can be exploited remotely by authenticated users.