CVE-2013-4729
import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file forma
import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authenticated users to modify the GLOBALS superglobal array, and consequently change the configuration, via a crafted request.
MEDIUM · CVSS 5.5
EPSS 0.00367
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0