peter bassill · operator
$ cve CVE-2011-4107 JSON

CVE-2011-4107 EXPLOIT

6.5
MEDIUM · CVSS 3.1 · EPSS 12.7% (pctl 96)

Patch early

A public exploit exists.

Description

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS12.67% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-611
On CISA KEVno
Public exploityes
Published2011-11-17
Last modified2026-06-16

Affected (3)

VendorProduct
debiandebian linux
fedoraprojectfedora
phpmyadminphpmyadmin

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD