First published: Tue Jul 30 2013(Updated: )
Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PhpMyAdmin | =3.5.0.0 | |
PhpMyAdmin | =3.5.1.0 | |
PhpMyAdmin | =3.5.2.0 | |
PhpMyAdmin | =3.5.2.1 | |
PhpMyAdmin | =3.5.2.2 | |
PhpMyAdmin | =3.5.3.0 | |
PhpMyAdmin | =3.5.4 | |
PhpMyAdmin | =3.5.5 | |
PhpMyAdmin | =3.5.6 | |
PhpMyAdmin | =3.5.7 | |
PhpMyAdmin | =3.5.7-rc1 | |
PhpMyAdmin | =3.5.8 | |
PhpMyAdmin | =3.5.8-rc1 | |
PhpMyAdmin | =3.5.8.1 | |
PhpMyAdmin | =4.0.0 | |
PhpMyAdmin | =4.0.0-rc2 | |
PhpMyAdmin | =4.0.0-rc3 | |
PhpMyAdmin | =4.0.1 | |
PhpMyAdmin | =4.0.2 | |
PhpMyAdmin | =4.0.3 | |
PhpMyAdmin | =4.0.4 | |
PhpMyAdmin | =4.0.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5003 has been classified as a high-severity vulnerability due to the potential for remote SQL injection attacks.
To fix CVE-2013-5003, you should upgrade phpMyAdmin to version 3.5.8.2 or later, or 4.0.4.2 or later.
CVE-2013-5003 affects phpMyAdmin versions 3.5.x prior to 3.5.8.2 and 4.0.x prior to 4.0.4.2.
CVE-2013-5003 allows remote authenticated users to execute arbitrary SQL commands using specific parameters in phpMyAdmin.
While upgrading is the recommended approach, you can also employ input validation and sanitization to reduce the risk of SQL injection.