Remote Variable Manipulation Vulnerability in Swekey Authentication Feature in phpMyAdmin

Remote Variable Manipulation Vulnerability in Swekey Authentication Feature in phpMyAdmin

CVE-2011-2505 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:P/A:P

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

Learn more about our Web Application Penetration Testing UK.