CVE-2010-4481

medium
Published 2010-12-17 ยท Modified 2025-04-12
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.0

Description

phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

debian Debian Fixed 4 releases
VersionStatusFixed in
trixie Fixed 4:3.3.7-3
sid Fixed 4:3.3.7-3
bullseye Fixed 4:3.3.7-3
bookworm Fixed 4:3.3.7-3

Package impact

EcosystemPackageVulnerableFixed
php Packagistphpmyadmin/phpmyadmin<3.4.0-beta13.4.0-beta1

Application impact

VendorProductVersionsFixed
phpmyadminphpmyadmin{"endIncluding":"3.3.9.0"}
phpmyadminphpmyadmin2.11.0
phpmyadminphpmyadmin2.11.1.0
phpmyadminphpmyadmin2.11.1.1
phpmyadminphpmyadmin2.11.1.2
phpmyadminphpmyadmin2.11.2.0
phpmyadminphpmyadmin2.11.2.1
phpmyadminphpmyadmin2.11.2.2
phpmyadminphpmyadmin2.11.3.0
phpmyadminphpmyadmin2.11.4.0
phpmyadminphpmyadmin2.11.5.0
phpmyadminphpmyadmin2.11.5.1
phpmyadminphpmyadmin2.11.5.2
phpmyadminphpmyadmin2.11.6.0
phpmyadminphpmyadmin2.11.7.0
phpmyadminphpmyadmin2.11.7.1
phpmyadminphpmyadmin2.11.8.0
phpmyadminphpmyadmin2.11.9.0
phpmyadminphpmyadmin2.11.9.1
phpmyadminphpmyadmin2.11.9.2
phpmyadminphpmyadmin2.11.9.3
phpmyadminphpmyadmin2.11.9.4
phpmyadminphpmyadmin2.11.9.5
phpmyadminphpmyadmin2.11.9.6
phpmyadminphpmyadmin2.11.10.0
phpmyadminphpmyadmin2.11.10.1
phpmyadminphpmyadmin3.0.0
phpmyadminphpmyadmin3.0.1
phpmyadminphpmyadmin3.0.1.1
phpmyadminphpmyadmin3.1.0
phpmyadminphpmyadmin3.1.1
phpmyadminphpmyadmin3.1.2
phpmyadminphpmyadmin3.1.3
phpmyadminphpmyadmin3.1.3.1
phpmyadminphpmyadmin3.1.3.2
phpmyadminphpmyadmin3.1.4
phpmyadminphpmyadmin3.1.5
phpmyadminphpmyadmin3.2.0
phpmyadminphpmyadmin3.2.1
phpmyadminphpmyadmin3.2.2
phpmyadminphpmyadmin3.3.0.0
phpmyadminphpmyadmin3.3.1.0
phpmyadminphpmyadmin3.3.2.0
phpmyadminphpmyadmin3.3.3.0
phpmyadminphpmyadmin3.3.4.0
phpmyadminphpmyadmin3.3.5.0
phpmyadminphpmyadmin3.3.5.1
phpmyadminphpmyadmin3.3.6
phpmyadminphpmyadmin3.3.7
phpmyadminphpmyadmin3.3.8
phpmyadminphpmyadmin3.3.8.1

References

CWEs

CWE-287

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.