Multiple Critical Security Vulnerabilities in phpMyAdmin 3.4.3 and Previous
phpMyAdmin is a browser-based MySQL database management application.
Affected Application: phpMyAdmin 3.4.3 and previous.
Please note that the vulnerabilities do not affect 2.11.x versions.
Our Linux shared hosting accounts currently have phpMyAdmin version 2.11.11.3 installed.
Issue: On 07/02/11, multiple critical security vulnerabilities were reported for phpMyAdmin version 3.4.3 and previous. The vulnerabilities could let attackers overwrite session information to bypass authentication, inject malicious code, or perform other actions.
Resolution: An update for phpMyAdmin is available. If you use phpMyAdmin 3.4.3 or previous on a virtual or dedicated server, you must download and install the patch or latest version. Visit the vendor's website for information:
http://www.phpmyadmin.net/home_page/index.php.
This information was compiled using the following phpMyAdmin security advisory articles:
Possible session manipulation in Swekey authentication.
Possible code injection in setup script in case session variables are compromised.
Regular expression quoting issue in Synchronize code.
Possible directory traversal.
Website Protection Site Scanner scans for this vulnerability, and many more. To learn about Site Scanner, see Getting Started with Website Protection Site Scanner.