HTTP: phpMyAdmin session_to_unset session variable injection attempt detected

This signature detects attempts to exploit a known vulnerability against phpMyAdmin. A successful attack can lead to arbitrary code execution.

Extended Description

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

Affected Products

Phpmyadmin phpmyadmin

References

CVE: CVE-2011-2506

Short Name
HTTP:PHP:PHPMYADMIN:VAR-INJECT
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2011-2505 CVE-2011-2506 attempt detected injection phpMyAdmin session session_to_unset variable
Release Date
08/26/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3650
False Positive
Unknown
Vendors

Phpmyadmin

CVSS Score

7.5

6.4

Found a potential security threat?