Total vulnerabilities in the database
import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authenticated users to modify the GLOBALS superglobal array, and consequently change the configuration, via a crafted request.
Software | From | Fixed in |
---|---|---|
phpmyadmin / phpmyadmin | 4.0.0 | 4.0.0.x |
phpmyadmin / phpmyadmin | 4.0.3 | 4.0.3.x |
phpmyadmin / phpmyadmin | 4.0.2 | 4.0.2.x |
phpmyadmin / phpmyadmin | 4.0.1 | 4.0.1.x |
phpmyadmin / phpmyadmin | 4.0.0-rc2 | 4.0.0-rc2.x |
phpmyadmin / phpmyadmin | 4.0.4 | 4.0.4.x |
phpmyadmin / phpmyadmin | 4.0.0-rc3 | 4.0.0-rc3.x |