First published: Mon Jul 25 2011(Updated: )
A local file inclusion flaw was found in the way phpMyAdmin, the MySQL over WWW administration tool, performed particular SQL query execution. A local attacker could use this flaw to obtain sensitive information via specially-crafted MIME-type transformation parameter. References: [1] <a href="http://www.phpmyadmin.net/home_page/security/PMASA-2011-10.php">http://www.phpmyadmin.net/home_page/security/PMASA-2011-10.php</a> [2] <a href="http://www.phpmyadmin.net/home_page/news.php">http://www.phpmyadmin.net/home_page/news.php</a> Upstream patches: [3] <a href="http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commitdiff;h=f63e1bb42a37401b2fdfcd2e66cce92b7ea2025c">http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commitdiff;h=f63e1bb42a37401b2fdfcd2e66cce92b7ea2025c</a> Versions affected: Versions 3.4.0 to 3.4.3.1 are affected. Further flaw exploitation details: The phpMyAdmin's configuration storage mechanism must be configured for this attack to work.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PhpMyAdmin | =3.4.0.0 | |
PhpMyAdmin | =3.4.3.1 | |
PhpMyAdmin | =3.4.1.0 | |
PhpMyAdmin | =3.4.2.0 | |
PhpMyAdmin | =3.4.3.0 | |
phpMyAdmin | =3.4.0.0 | |
phpMyAdmin | =3.4.1.0 | |
phpMyAdmin | =3.4.2.0 | |
phpMyAdmin | =3.4.3.0 | |
phpMyAdmin | =3.4.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2643 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2011-2643, update phpMyAdmin to the latest version that addresses this vulnerability.
The affected versions include phpMyAdmin 3.4.0.0, 3.4.1.0, 3.4.2.0, 3.4.3.0, and 3.4.3.1.
CVE-2011-2643 is a local file inclusion vulnerability affecting phpMyAdmin.
CVE-2011-2643 requires local access by an attacker to exploit the vulnerability.