Server side template injection In phpmyadmin/phpmyadmin
Description
phpMyAdmin Remote Code Execution phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename of an export file, leading to interpretation of this file as an executable file by the Apache HTTP Server, as demonstrated by a .php.sql filename.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 3.5.8.1 | ||
debian 13 | 4:3.4.11.1-2 | ||
debian 11 | 4:3.4.11.1-2 | ||
debian 12 | 4:3.4.11.1-2 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8.