The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2011-11-17T19:00:00
Updated: 2017-08-28T12:57:01
Reserved: 2011-10-18T00:00:00
Link: CVE-2011-4107
JSON object: View
NVD Information
Status : Analyzed
Published: 2011-11-17T19:55:01.517
Modified: 2024-02-09T02:27:11.997
Link: CVE-2011-4107
JSON object: View
Redhat Information
No data.
CWE