VULNERABILITY INTELLIGENCE
CVE-2011-4107
CVSS score6.5 MEDIUM
EPSS probability12.68%
CISA KEVNot currently listed
Published2011-11-17
Last modified2026-06-16
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
Weakness classification
- CWE-611: Improper Restriction of XML External Entity Reference
Primary references
- secalert@redhat.com — Mailing List, Third Party Advisory
- secalert@redhat.com — Mailing List, Third Party Advisory
- secalert@redhat.com — Mailing List, Third Party Advisory
- secalert@redhat.com — Broken Link
- secalert@redhat.com — Broken Link, Exploit
- secalert@redhat.com — Exploit, Mailing List, Third Party Advisory
- secalert@redhat.com — Broken Link, Vendor Advisory
- secalert@redhat.com — Broken Link
- secalert@redhat.com — Mailing List
- secalert@redhat.com — Broken Link
- secalert@redhat.com — Mailing List
- secalert@redhat.com — Mailing List