This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

phpMyAdmin - updates/advisories

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

phpMyAdmin v2.11.10.1 released
- http://secunia.com/advisories/41058/
Release Date: 2010-08-20
CVE Reference: CVE-2010-3055
… The vulnerability is reported in versions prior to 2.11.10.1.
Solution: Update to version 2.11.10.1…
Original Advisory: phpMyAdmin:
http://www.phpmyadmin.net/home_page/securi…MASA-2010-4.php
2010-08-20 - "… We consider this vulnerability to be critical…"

- http://secunia.com/advisories/41000/
Release Date: 2010-08-20
CVE Reference: CVE-2010-3056
… The vulnerabilities are reported in versions prior to 3.3.5.1 and 2.11.10.1…
Solution: Update to version 3.3.5.1 or 2.11.10.1…
http://www.phpmyadmin.net/home_page/securi…MASA-2010-5.php
2010-08-20 - "… We consider this vulnerability to be serious…"

- http://secunia.com/advisories/41075/
Release Date: 2010-08-23
FEDORA-2010-13258:
http://lists.fedoraproject.org/pipermail/p…ust/045997.html
FEDORA-2010-13249:
http://lists.fedoraproject.org/pipermail/p…ust/045991.html

- http://www.phpmyadmin.net/home_page/index.php

- http://www.theregister.co.uk/2010/08/12/server_based_botnet/
Updated - 12 August 2010

- http://isc.sans.edu/diary.html?storyid=9370
Last Updated: 2010-08-13 16:51:28 UTC …(Version: 5)

:ph34r: :ph34r:
FYI…

phpMyAdmin - multiple vulns - updates released
- http://secunia.com/advisories/45139/
Release Date: 2011-07-05
Criticality level: Highly critical
Impact: Exposure of system information, Exposure of sensitive information, System access
Where: From remote
CVE Reference(s): CVE-2011-2505, CVE-2011-2506, CVE-2011-2507
Solution: Update to version 3.3.10.2 or 3.4.3.1.
Original Advisory:
http://www.phpmyadmin.net/home_page/securi…MASA-2011-5.php
http://www.phpmyadmin.net/home_page/securi…MASA-2011-6.php
http://www.phpmyadmin.net/home_page/securi…MASA-2011-7.php
http://www.phpmyadmin.net/home_page/securi…MASA-2011-8.php

- http://www.h-online.com/security/news/item…es-1273593.html
5 July 2011 - "… According to the developers, the above vulnerabilities could lead to the injection and execution of arbitrary code…"

:ph34r: :ph34r:
FYI…

phpMyAdmin multiple vulns
- http://secunia.com/advisories/45365/
Release Date: 2011-07-25
Criticality level: Highly critical
Impact: Cross Site Scripting, Exposure of sensitive information, System access
Where: From remote
CVE Reference(s): CVE-2011-2642, CVE-2011-2643 …
Solution: Update to version 3.3.10.3 or 3.4.3.2.
Original Advisory:
PMASA-2011-9: http://www.phpmyadmin.net/home_page/securi…MASA-2011-9.php
PMASA-2011-10: http://www.phpmyadmin.net/home_page/securi…ASA-2011-10.php
PMASA-2011-11: http://www.phpmyadmin.net/home_page/securi…ASA-2011-11.php
PMASA-2011-12: http://www.phpmyadmin.net/home_page/securi…ASA-2011-12.php

- http://h-online.com/-1285281
25 July 2011

:ph34r:
FYI…

phpMyAdmin v3.4.4 released
- http://h-online.com/-1331093
25 August 2011 - "… maintenance and security updates close a hole (CVE-2011-3181) in the Tracking feature that leads to multiple cross-site scripting (XSS) vulnerabilities… Versions 3.3.0 to 3.4.3.2 are affected and the developers consider the problem to be serious. Updating to phpMyAdmin 3.3.10.4 or 3.4.4 fixes the problem…"

Download
- http://www.phpmyadmin.net/home_page/downloads.php

- http://www.phpmyadmin.net/home_page/downlo…p#distributions

Bugfixes…
- http://sourceforge.net/projects/phpmyadmin…3.4.4.html/view

- http://sourceforge.net/projects/phpmyadmin/
Release Date: 2011-08-24

:ph34r:
FYI…

phpMyAdmin v3.4.6 released
- http://www.securitytracker.com/id/1026199
CVE Reference: CVE-2011-4064
Date: Oct 18 2011
Version(s): 3.4.x prior to 3.4.6 …
… A remote user can conduct cross-site scripting attacks… vendor has issued a fix (3.4.6).
The vendor's advisory is available at:
http://www.phpmyadmin.net/home_page/securi…ASA-2011-16.php
___

- http://blog.sucuri.net/2011/10/remove-unsu…-your-site.html
October 20, 2011

:blink:
FYI…

phpMyAdmin v3.4.7.1 - v3.3.10.5 updates released
- http://www.phpmyadmin.net/home_page/securi…ASA-2011-17.php
Announcement-ID: PMASA-2011-17
Date: 2011-11-10
Summary: Local file inclusion.
Description: Importing a specially-crafted XML file which contains an XML entity injection permits to retrieve a local file (limited by the privileges of the user running the web server).
Severity: We consider this vulnerability to be serious.
Mitigation factor: The attacker must be logged in to MySQL via phpMyAdmin.
Affected Versions: Versions 3.3.x and 3.4.x are affected.
Solution: Upgrade to phpMyAdmin 3.4.7.1 or newer (or 3.3.10.5) or apply the related patches…

- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2011-4107
Last revised: 11/18/2011
"… phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5…"

:ph34r:
FYI…

phpMyAdmin v3.4.9 released
- http://h-online.com/-1400135
22 December 2011 - "… fixes vulnerabilities in the phpMyAdmin setup interface and the export panels in the server, database and table sections that could be exploited for cross-site scripting (XSS) attacks. All 3.4.x versions up to and including 3.4.8 are affected – upgrading to 3.4.9 corrects the issues. Alternatively, patches are provided. The new release also fixes nine other bugs related to navigation, the user interface and the edit functionality…"

PMASA-2011-19
- http://www.phpmyadmin.net/home_page/securi…ASA-2011-19.php
PMASA-2011-20
- http://www.phpmyadmin.net/home_page/securi…ASA-2011-20.php

Release notes
- http://sourceforge.net/projects/phpmyadmin…notes.html/view
… phpMyAdmin 3.4.9, a bugfix release with minor security corrections.
3.4.9.0 (2011-12-21)

- http://www.phpmyadmin.net/home_page/downloads.php

:ph34r:
FYI…

phpMyAdmin 3.x - potential compromise
- https://secunia.com/advisories/50703/
Release Date: 2012-09-25
Criticality level: Extremely critical
Impact: System access
Where: From remote
… distribution of a compromised phpMyAdmin source code package containing a backdoor, which can be exploited to e.g. execute arbitrary PHP code.
Solution: Download and reinstall phpMyAdmin.
Software: phpMyAdmin 3.x
Original Advisory:
http://www.phpmyadmin.net/home_page/securi…MASA-2012-5.php
Date: 2012-09-25
Summary: One server from the SourceForge.net mirror system was distributing a phpMyAdmin kit containing a backdoor…
Severity: We consider this vulnerability to be critical.
Affected Versions: We currently know only about phpMyAdmin-[removed]-all-languages.zip being affected, check if your download contains a file named server_sync.php.
Solution: Check your phpMyAdmin distribution and download it again from a trusted mirror if your copy contains a file named server_sync.php…

> http://www.phpmyadmin.net/home_page/downloads.php
phpMyAdmin 3.5.2.2 - Released 12 Aug 2012
___

- https://threatpost.com/en_us/blogs/sourcefo…pmyadmin-092512
Sep 25, 2012

- http://h-online.com/-1717644
26 Sep 2012

:ph34r: :ph34r: :ph34r:
FYI…

phpMyAdmin - 3.5.8.2 + 4.0.4.2
- https://secunia.com/advisories/54295/
Release Date: 2013-07-29
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Solution Status: Vendor Patch
Software: phpMyAdmin 3.x, 4.x
Solution: Update to version 3.5.8.2 or 4.0.4.2.
Original Advisory:
http://www.phpmyadmin.net/home_page/securi…MASA-2013-9.php
http://www.phpmyadmin.net/home_page/securi…ASA-2013-13.php
http://www.phpmyadmin.net/home_page/securi…ASA-2013-15.php

:ph34r:

FYI…

phpMyAdmin 4.6.2, 4.4.15.6 released
- https://www.phpmyadmin.net/security/PMASA-2016-14/
2016-05-25

> http://www.securitytracker.com/id/1035978
CVE Reference: CVE-2016-5097
May 27 2016
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to 4.6.2 …
___

- https://www.phpmyadmin.net/security/PMASA-2016-15/
2016-05-25

> http://www.securitytracker.com/id/1035980
CVE Reference: CVE-2016-5098
May 27 2016
Fix Available:  Yes  Vendor Confirmed:  Yes  
___

- https://www.phpmyadmin.net/security/PMASA-2016-16/
2016-05-25

> http://www.securitytracker.com/id/1035979
CVE Reference: CVE-2016-5099
May 27 2016
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 4.4.x prior to 4.4.15.6, 4.6.x prior to 4.6.2 …
___

Downloads
> https://www.phpmyadmin.net/downloads/

phpMyAdmin 4.6.2
- https://www.phpmyadmin.net/news/2016/5/26/phpmyadmin-462-released/
2016-05-26
Release notes
- https://www.phpmyadmin.net/files/4.6.2/

phpMyAdmin 4.4.15.6
- https://www.phpmyadmin.net/news/2016/5/26/phpmyadmin-security-notifications-and-44156-released/
2016-05-26
Release notes
- https://www.phpmyadmin.net/files/4.4.15.6/
 

:ph34r: :ph34r: :ph34r: