peter bassill · operator
$ cve CVE-2011-2506 JSON

CVE-2011-2506 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 9.6% (pctl 95)

Patch early

A public exploit exists.

Description

setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS9.63% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2011-07-14
Last modified2026-06-16

Affected (1)

VendorProduct
phpmyadminphpmyadmin

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD