Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2011-4107

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.115
EPSS Ranking 93.2%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.3
References
Products affected by CVE-2011-4107


Contact Us

Shodan ® - All rights reserved