CVE-2013-3238
phpMyAdmin - 'preg_replace' (Authenticated) Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a preg_replace function call within the "Replace table prefix" feature.
phpMyAdmin v3.5.x antes de v3.5.8 y v4.x antes de v4.0.0-RC3 permite a usuarios remotos autenticados ejecutar código arbitrario a través de una secuencia /e\x00, que no se utilizan con cuidado antes de hacer una llamada a la función preg_replace en el "Replace table prefix".
Multiple vulnerabilities have been found in phpMyAdmin, allowing remote authenticated attackers to execute arbitrary code, inject SQL code or conduct other attacks. Versions less than 4.0.5 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-04-22 CVE Reserved
- 2013-04-25 First Exploit
- 2013-04-26 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2013-04/0217.html | Mailing List | |
http://www.phpmyadmin.net/home_page/security/PMASA-2013-2.php | X_refsource_confirm | |
https://github.com/phpmyadmin/phpmyadmin/commit/dedd542cdaf1606ca9aa3f6f8f8adb078d8ad549 | X_refsource_confirm | |
https://github.com/phpmyadmin/phpmyadmin/commit/ffa720d90a79c1f33cf4c5a33403d09a67b42a66 | X_refsource_confirm | |
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0133 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/25136 | 2013-05-01 | |
https://www.exploit-db.com/exploits/25003 | 2013-04-25 | |
http://www.exploit-db.com/exploits/25136 | 2024-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.5.0.0 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.5.0.0" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.5.1.0 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.5.1.0" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.5.2.0 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.5.2.0" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.5.2.1 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.5.2.1" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.5.2.2 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.5.2.2" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.5.3.0 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.5.3.0" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.5.4 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.5.4" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.5.5 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.5.5" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.5.6 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.5.6" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.5.7 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.5.7" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.5.7 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.5.7" | rc1 |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 3.5.8 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "3.5.8" | rc1 |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.0 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.0" | rc2 |
Affected
|