Total vulnerabilities in the database
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
Software | From | Fixed in |
---|---|---|
phpmyadmin / phpmyadmin | - | 2.11.5.1 |
debian / debian_linux | 4.0 | 4.0.x |
fedoraproject / fedora | 8 | 8.x |
fedoraproject / fedora | 7 | 7.x |
opensuse / opensuse | 10.2 | 10.2.x |
opensuse / opensuse | 11.0 | 11.0.x |
opensuse / opensuse | 10.3 | 10.3.x |