CVE-2011-4107
medium · 6.5The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
6.5
CVSS
12.7%
EPSS (exploit prob.)
96th
EPSS percentile
2011-11-17
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-611
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| phpmyadmin | phpmyadmin | >= 3.3.0.0, < 3.3.10.5 |
| phpmyadmin | phpmyadmin | >= 3.4.0.0, < 3.4.7.1 |
| fedoraproject | fedora | 14 |
| fedoraproject | fedora | 15 |
| fedoraproject | fedora | 16 |
| debian | debian_linux | 5.0 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069625.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069635.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069649.html
- http://osvdb.org/76798
- http://packetstormsecurity.org/files/view/106511/phpmyadmin-fileread.txt
- http://seclists.org/fulldisclosure/2011/Nov/21
- http://secunia.com/advisories/46447
- http://securityreason.com/securityalert/8533
- http://www.debian.org/security/2012/dsa-2391
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:198
- http://www.openwall.com/lists/oss-security/2011/11/03/3
- http://www.openwall.com/lists/oss-security/2011/11/03/5
- http://www.phpmyadmin.net/home_page/security/PMASA-2011-17.php
- http://www.securityfocus.com/bid/50497
- http://www.wooyun.org/bugs/wooyun-2010-03185
- https://bugzilla.redhat.com/show_bug.cgi?id=751112
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71108
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069625.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069635.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069649.html
- http://osvdb.org/76798
- http://packetstormsecurity.org/files/view/106511/phpmyadmin-fileread.txt
- http://seclists.org/fulldisclosure/2011/Nov/21
- http://secunia.com/advisories/46447
- http://securityreason.com/securityalert/8533
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-4107