GHSA-xhqq-554j-p4x8

Suggest an improvement
Source
https://github.com/advisories/GHSA-xhqq-554j-p4x8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xhqq-554j-p4x8/GHSA-xhqq-554j-p4x8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xhqq-554j-p4x8
Aliases
Published
2022-05-17T01:54:30Z
Modified
2024-01-15T18:41:35.561503Z
Summary
phpMyAdmin Directory Traversal Vulnerability
Details

Multiple directory traversal vulnerabilities in the relational schema implementation in phpMyAdmin 3.4.x before 3.4.3.2 allow remote authenticated users to include and execute arbitrary local files via directory traversal sequences in an export type field, related to (1) libraries/schema/User_Schema.class.php and (2) schema_export.php.

Database specific
{
    "nvd_published_at": "2011-08-01T19:55:00Z",
    "cwe_ids": [
        "CWE-22"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-15T18:15:49Z"
}
References

Affected packages

Packagist / phpmyadmin/phpmyadmin

Package

Name
phpmyadmin/phpmyadmin
Purl
pkg:composer/phpmyadmin/phpmyadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.4
Fixed
3.4.3.2