CVE-2011-3646: Input Validation
Published Nov 17, 2011
·Updated
phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed jsframe parameter to phpmyadmin.css.php, which reveals the installation path in an error message.
Affected Software
8 affected components
phpMyAdmin phpMyAdmin=3.4.5.0
phpMyAdmin phpMyAdmin=3.4.0.0
phpMyAdmin phpMyAdmin=3.4.3.1
phpMyAdmin phpMyAdmin=3.4.4.0
phpMyAdmin phpMyAdmin=3.4.1.0
phpMyAdmin phpMyAdmin=3.4.2.0
phpMyAdmin phpMyAdmin=3.4.3.0
phpMyAdmin phpMyAdmin=3.4.3.2
Remediation
Event History
Nov 17, 2011
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3646?
CVE-2011-3646 has a low severity rating as it primarily discloses sensitive information without allowing direct system compromise.
2
How do I fix CVE-2011-3646?
To fix CVE-2011-3646, upgrade phpMyAdmin to version 3.4.6 or later where the vulnerability is patched.
3
What versions of phpMyAdmin are affected by CVE-2011-3646?
CVE-2011-3646 affects phpMyAdmin versions 3.4.0.0 through 3.4.5.0.
4
What kind of information can be leaked due to CVE-2011-3646?
CVE-2011-3646 can leak the installation path of phpMyAdmin in error messages.
5
Who can exploit CVE-2011-3646?
Remote attackers can exploit CVE-2011-3646 by sending crafted requests to phpMyAdmin.