LWN.net Logo

phpMyAdmin: arbitrary file reading

Package(s):phpMyAdmin CVE #(s):CVE-2011-4107
Created:November 23, 2011 Updated:January 2, 2012
Description:

From the CVE entry:

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

Alerts:
Fedora FEDORA-2011-15841 2011-11-13
Fedora FEDORA-2011-15846 2011-11-13
Fedora FEDORA-2011-15831 2011-11-13
Mandriva MDVSA-2011:198 2011-12-31
Gentoo 201201-01 2012-01-04
Debian DSA-2391-1 2012-01-22

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds