LWN.net Logo

phpmyadmin: multiple vulnerabilities

Package(s):phpmyadmin CVE #(s):CVE-2011-0986 CVE-2011-0987
Created:February 14, 2011 Updated:February 25, 2011
Description: From the Mandriva advisory:

When the files README, ChangeLog or LICENSE have been removed from their original place (possibly by the distributor), the scripts used to display these files can show their full path, leading to possible further attacks (CVE-2011-0986).

It was possible to create a bookmark which would be executed unintentionally by other users (CVE-2011-0987).

Alerts:
Fedora FEDORA-2011-1373 2011-02-13
Fedora FEDORA-2011-1408 2011-02-13
Debian DSA-2167-1 2011-02-16
Mandriva MDVSA-2011:026 2011-02-14
Gentoo 201201-01 2012-01-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds