Release date: 2011-11-02
Updated on: 2011-11-03
Affected Systems:
PhpMyAdmin 3.x
PhpMyAdmin 2.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50497
PhpMyAdmin is written in PHP and can be used to control and operate MySQL databases on the web.
PhpMyAdmin has the information leakage vulnerability in the implementation of simplexml_load_string () function. Attackers can exploit this vulnerability to read arbitrary files on the server.
<* Source: WooYun
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PhpMyAdmin
----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.phpmyadmin.net/home_page/security/