CVE-2010-3055
phpmyadmin - several vulnerabilities
EPSS 1.7%
Description
The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.
How to fix CVE-2010-3055
To remediate CVE-2010-3055, upgrade the affected package to a fixed version below.
- Debian/phpmyadmin—upgrade to 4:3.0.0 or later
- Debian/phpmyadmin—upgrade to 4:2.11.8.1-5+lenny5 or later
- Debian/phpmyadmin—upgrade to 4:2.11.8.1-5+lenny6 or later
Is CVE-2010-3055 being exploited?
Low — EPSS is 1.7%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 4:3.0.0
- from 0, < 4:2.11.8.1-5+lenny5
- from 0, < 4:2.11.8.1-5+lenny6