CVE Database
/

CVE-2011-4107

Back to search

CVE-2011-4107

Published: Nov 17, 2011

Modified: Aug 7, 2024

PUBLISHED

Description

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

VendorProductVersions

n/a

n/a

affected
n/a

References

46447
third-party-advisory
x_refsource_SECUNIA
76798
vdb-entry
x_refsource_OSVDB
FEDORA-2011-15846
vendor-advisory
x_refsource_FEDORA
20111102 PhpMyAdmin Arbitrary File Reading
mailing-list
x_refsource_FULLDISC
DSA-2391
vendor-advisory
x_refsource_DEBIAN
FEDORA-2011-15831
vendor-advisory
x_refsource_FEDORA
50497
vdb-entry
x_refsource_BID
MDVSA-2011:198
vendor-advisory
x_refsource_MANDRIVA
8533
third-party-advisory
x_refsource_SREASON
FEDORA-2011-15841
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now