CVE-2013-5003

NameCVE-2013-5003
DescriptionMultiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-0014-1, DSA-2975-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
phpmyadmin (PTS)bullseye4:5.0.4+dfsg2-2+deb11u1fixed
bookworm4:5.2.1+dfsg-1fixed
trixie4:5.2.2-really5.2.2+20241130+dfsg-1fixed
sid4:5.2.2-really5.2.2+20241228+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
phpmyadminsourcesqueeze4:3.3.7-8
phpmyadminsourcewheezy4:3.4.11.1-2+deb7u1DSA-2975-1
phpmyadminsource(unstable)4:4.0.4.2-1

Search for package or bug name: Reporting problems