Server side template injection In phpmyadmin
Description
An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the file generator_plugin.sh. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.2 | 4.4.15.8-r0 | ||
debian 11 | 4:4.6.4+dfsg1-1 | ||
debian 12 | 4:4.6.4+dfsg1-1 | ||
debian 13 | 4:4.6.4+dfsg1-1 | ||
debian 14 | 4:4.6.4+dfsg1-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.