CVE-2013-3239

medium
Published 2013-04-26 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v2
4.6
VIR risk
4.6

Description

phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-3239

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/1f6bc0b707002e26cab216b9e57b4d5de764de48

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.phpmyadmin.net/home_page/security/PMASA-2013-3.php

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4:3.4.11.1-2
debian debianbullseyefixed4:3.4.11.1-2
debian debiansidfixed4:3.4.11.1-2
debian debiantrixiefixed4:3.4.11.1-2

Package impact

EcosystemPackageVulnerableFixed
php Packagistphpmyadmin/phpmyadmin>=3.5.0,<3.5.8.13.5.8.1

Application impact

VendorProductVersionsFixed
phpmyadminphpmyadmin3.5.0.0
phpmyadminphpmyadmin3.5.1.0
phpmyadminphpmyadmin3.5.2.0
phpmyadminphpmyadmin3.5.2.1
phpmyadminphpmyadmin3.5.2.2
phpmyadminphpmyadmin3.5.3.0
phpmyadminphpmyadmin3.5.4
phpmyadminphpmyadmin3.5.5
phpmyadminphpmyadmin3.5.6
phpmyadminphpmyadmin3.5.7
phpmyadminphpmyadmin3.5.8
phpmyadminphpmyadmin4.0.0

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.