CVE-2011-4107 EXPLOIT
6.5
MEDIUM · CVSS 3.1 · EPSS 12.7% (pctl 96)
Patch early
A public exploit exists.
Description
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
Scoring
| CVSS | 6.5 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 12.67% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-611 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-11-17 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| debian | debian linux |
| fedoraproject | fedora |
| phpmyadmin | phpmyadmin |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | phpMyAdmin 3.3.x/3.4.x - Local File Inclusion via XML External Entity Injection (Metasploit) | 2012-01-14 |
References
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069625.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069635.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069649.html
- http://osvdb.org/76798
- http://packetstormsecurity.org/files/view/106511/phpmyadmin-fileread.txt
- http://seclists.org/fulldisclosure/2011/Nov/21
- http://secunia.com/advisories/46447
- http://securityreason.com/securityalert/8533
- http://www.debian.org/security/2012/dsa-2391
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:198
- http://www.openwall.com/lists/oss-security/2011/11/03/3
- http://www.openwall.com/lists/oss-security/2011/11/03/5
- http://www.phpmyadmin.net/home_page/security/PMASA-2011-17.php
- http://www.securityfocus.com/bid/50497
- http://www.wooyun.org/bugs/wooyun-2010-03185
- https://bugzilla.redhat.com/show_bug.cgi?id=751112
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71108
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069625.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069635.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069649.html
→ the Explorer · watch your stack · NVD