Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpMyAdmin ‘filename_template’远程代码执行漏洞
Vulnerability Description
phpMyAdmin是phpMyAdmin团队开发的一套免费的、基于Web的MySQL数据库管理工具。该工具能够创建和删除数据库,创建、删除、修改数据库表,执行SQL脚本命令等。 phpMyAdmin 3.5.8之前的3.5.x版本和4.0.0-rc3之前的4.x版本中存在漏洞。当配置SaveDir后,经过身份验证的远程攻击者可通过在导出文件后缀名后再加一后缀名,利用该漏洞执行任意代码,导致Apache HTTP服务器认为该文件可执行。例如:.php.sql的文件后缀名。
CVSS Information
N/A
Vulnerability Type
N/A