CVE-2011-4107

NameCVE-2011-4107
DescriptionThe simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2391-1
NVD severitymedium
Debian Bugs656247

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
phpmyadmin (PTS)stretch4:4.6.6-4+deb9u1fixed
bullseye, sid4:4.9.5+dfsg1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
phpmyadminsourcelenny(not affected)
phpmyadminsourcesqueeze4:3.3.7-7DSA-2391-1
phpmyadminsource(unstable)4:3.4.7.1-1656247

Notes

[lenny] - phpmyadmin <not-affected> (Vulnerable code not present)
https://bugzilla.redhat.com/show_bug.cgi?id=751112

Search for package or bug name: Reporting problems