FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-4107

This CVE name corresponds to:

Entered Topic
2011-11-12 phpmyadmin -- Local file inclusion

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-4107
Phase Assigned(20111018)

Description

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

References

Source Reference
FULLDISC 20111102 PhpMyAdmin Arbitrary File Reading
MLIST [oss-security] 20111103 CVE Request -- phpMyAdmin -- Arbitrary local file read flaw by loading XML strings / importing XML files
MLIST [oss-security] 20111103 Re: CVE Request -- phpMyAdmin -- Arbitrary local file read flaw by loading XML strings / importing XML files
MISC http://packetstormsecurity.org/files/view/106511/phpmyadmin-fileread.txt
MISC http://www.wooyun.org/bugs/wooyun-2010-03185
MISC https://bugzilla.redhat.com/show_bug.cgi?id=751112
CONFIRM http://www.phpmyadmin.net/home_page/security/PMASA-2011-17.php
DEBIAN DSA-2391
FEDORA FEDORA-2011-15831
FEDORA FEDORA-2011-15841
FEDORA FEDORA-2011-15846
MANDRIVA MDVSA-2011:198
BID 50497
OSVDB 76798
SECUNIA 46447
SREASON 8533
XF phpmyadmin-xml-info-disclosure(71108)