phpMyAdmin v2.11.10.1 released
- http://secunia.com/advisories/41058/
Release Date: 2010-08-20
CVE Reference: CVE-2010-3055
… The vulnerability is reported in versions prior to 2.11.10.1.
Solution: Update to version 2.11.10.1…
Original Advisory: phpMyAdmin: http://www.phpmyadmin.net/home_page/securi…MASA-2010-4.php
2010-08-20 - "… We consider this vulnerability to be critical…"
phpMyAdmin vuln - updates available
- http://secunia.com/advisories/42408/
Release Date: 2010-11-30
Impact: Cross Site Scripting
Where: From remote
Solution Status: Vendor Patch
Software: phpMyAdmin 2.x, phpMyAdmin 3.x
Solution: Update to version 2.11.11.1 or version 3.3.8.1.
Original Advisory: PMASA-2010-8: http://www.phpmyadmin.net/home_page/securi…MASA-2010-8.php
Date: 2010-11-29
phpMyAdmin v3.4.4 released
- http://h-online.com/-1331093
25 August 2011 - "… maintenance and security updates close a hole (CVE-2011-3181) in the Tracking feature that leads to multiple cross-site scripting (XSS) vulnerabilities… Versions 3.3.0 to 3.4.3.2 are affected and the developers consider the problem to be serious. Updating to phpMyAdmin 3.3.10.4 or 3.4.4 fixes the problem…"
phpMyAdmin v3.4.7.1 - v3.3.10.5 updates released
- http://www.phpmyadmin.net/home_page/securi…ASA-2011-17.php
Announcement-ID: PMASA-2011-17
Date: 2011-11-10
Summary: Local file inclusion.
Description: Importing a specially-crafted XML file which contains an XML entity injection permits to retrieve a local file (limited by the privileges of the user running the web server).
Severity: We consider this vulnerability to be serious.
Mitigation factor: The attacker must be logged in to MySQL via phpMyAdmin.
Affected Versions: Versions 3.3.x and 3.4.x are affected.
Solution: Upgrade to phpMyAdmin 3.4.7.1 or newer (or 3.3.10.5) or apply the related patches…
phpMyAdmin v3.4.9 released
- http://h-online.com/-1400135
22 December 2011 - "… fixes vulnerabilities in the phpMyAdmin setup interface and the export panels in the server, database and table sections that could be exploited for cross-site scripting (XSS) attacks. All 3.4.x versions up to and including 3.4.8 are affected – upgrading to 3.4.9 corrects the issues. Alternatively, patches are provided. The new release also fixes nine other bugs related to navigation, the user interface and the edit functionality…"
phpMyAdmin 3.x - potential compromise
- https://secunia.com/advisories/50703/
Release Date: 2012-09-25
Criticality level: Extremely critical
Impact: System access
Where: From remote
… distribution of a compromised phpMyAdmin source code package containing a backdoor, which can be exploited to e.g. execute arbitrary PHP code.
Solution: Download and reinstall phpMyAdmin.
Software: phpMyAdmin 3.x
Original Advisory: http://www.phpmyadmin.net/home_page/securi…MASA-2012-5.php
Date: 2012-09-25
Summary: One server from the SourceForge.net mirror system was distributing a phpMyAdmin kit containing a backdoor…
Severity: We consider this vulnerability to be critical.
Affected Versions: We currently know only about phpMyAdmin-[removed]-all-languages.zip being affected, check if your download contains a file named server_sync.php.
Solution: Check your phpMyAdmin distribution and download it again from a trusted mirror if your copy contains a file named server_sync.php…