CVE-2013-3238

Publication date 26 April 2013

Last updated 24 July 2024


Ubuntu priority

phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a preg_replace function call within the "Replace table prefix" feature.

Read the notes from the security team

Status

Package Ubuntu Release Status
phpmyadmin 13.04 raring
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Not affected
11.10 oneiric
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Ignored end of life

Notes


jdstrand

per Debian, PHP on Windows only