Lucene search

K
osvGoogleOSV:GHSA-WPWW-HX7X-XFJH
HistoryMay 14, 2022 - 3:14 a.m.

phpMyAdmin PHP code injection

2022-05-1403:14:46
Google
osv.dev
7
phpmyadmin
code injection
database name
arbitrary php commands

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

57.3%

An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.