Candidate: CVE-2010-4481 PublicDate: 2010-12-17 19:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4481 http://www.phpmyadmin.net/home_page/security/PMASA-2010-10.php Description: phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/phpmyadmin/+bug/696857 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_phpmyadmin: upstream: http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commitdiff;h=4d9fd005671b05c4d74615d5939ed45e4d019e4c upstream_phpmyadmin: released (4:3.3.7-3, 4:3.3.9-1, 3.4.0-beta1) dapper_phpmyadmin: ignored (reached end-of-life) hardy_phpmyadmin: ignored (reached end-of-life) karmic_phpmyadmin: ignored (reached end-of-life) lucid_phpmyadmin: ignored (reached end-of-life) maverick_phpmyadmin: released (4:3.3.7-3build0.10.10.1) natty_phpmyadmin: not-affected (4:3.3.10-1) oneiric_phpmyadmin: not-affected precise_phpmyadmin: not-affected quantal_phpmyadmin: not-affected raring_phpmyadmin: not-affected saucy_phpmyadmin: not-affected devel_phpmyadmin: not-affected