phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function.
http://www.vupen.com/english/advisories/2011/0027
http://www.vupen.com/english/advisories/2011/0001
http://www.vupen.com/english/advisories/2010/3238
http://www.phpmyadmin.net/home_page/security/PMASA-2010-10.php
http://www.mandriva.com/security/advisories?name=MDVSA-2011:000
http://www.debian.org/security/2010/dsa-2139
http://secunia.com/advisories/42725
Published: 2010-12-17
Updated: 2025-04-11
Base Score: 5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
Severity: Medium
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity: High
Base Score: 8
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Severity: High