Описание
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Broken Link
- Broken LinkExploit
- ExploitMailing ListThird Party Advisory
- Broken LinkVendor Advisory
- Broken Link
- Mailing List
- Broken Link
- Mailing List
- Mailing List
- PatchVendor Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkExploit
- ExploitIssue Tracking
- Third Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
The simplexml_load_string function in the XML import plug-in (librarie ...
phpMyAdmin vulnerable to XML external entity (XXE) injection attack
EPSS
6.5 Medium
CVSS3
4.3 Medium
CVSS2