CVE-2010-3055
phpmyadmin - several vulnerabilities
EPSS 14.7%
Description
The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.
How to fix CVE-2010-3055
To remediate CVE-2010-3055, upgrade the affected package to a fixed version below.
- Debian/phpmyadmin—upgrade to 4:3.0.0 or later
- Debian/phpmyadmin—upgrade to 4:2.11.8.1-5+lenny5 or later
- Debian/phpmyadmin—upgrade to 4:2.11.8.1-5+lenny6 or later
Is CVE-2010-3055 being exploited?
Moderate — EPSS is 14.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 4:3.0.0
- from 0, < 4:2.11.8.1-5+lenny5
- from 0, < 4:2.11.8.1-5+lenny6