Sploitus

CVE-2013-3239

6 known exploits for CVE-2013-3239

phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.

Affected products
Apache Http Server, Phpmyadmin
Phpmyadmin
= 3.5.0.0, 3.5.1.0, 3.5.2.0, 3.5.2.1, 3.5.2.2, 3.5.3.0, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 4.0.0
Fix
Available
CVSS 2.0
4.6 MEDIUM
EPSS
8.8% (95th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2013-04-26
CVE-2013-3239 at NVD
Authoritative description, scoring and affected products

6 known exploits for CVE-2013-3239

Proof-of-concept code and exploit modules indexed by Sploitus