<?xml-stylesheet type="text/css" href="http://www.phpmyadmin.net/home_page/css/feed.css"?><rss xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
<channel>
<atom:link href="http://www.phpmyadmin.net/home_page/security/index.xml" rel="self" type="application/rss+xml"></atom:link>
<title>phpMyAdmin security announcements</title>
<link>http://www.phpmyadmin.net/security/</link>
<description>phpMyAdmin security announcements</description>
<dc:language>en-us</dc:language>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:date>2013-05-20T05:22:03+00:00</dc:date>
<admin:generatorAgent rdf:resource="http://www.phpmyadmin.net"></admin:generatorAgent>
<item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2013-5.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2013-5.php</link>
<title>PMASA-2013-5</title>
<dc:date>2013-04-24T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Global variables overwrite in "export.php".
</p>
<h3>Affected Versions</h3>
<p>
phpMyAdmin versions 4.x (prior to 4.0.0-rc3).
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3241">CVE-2013-3241</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2013-4.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2013-4.php</link>
<title>PMASA-2013-4</title>
<dc:date>2013-04-24T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Local file inclusion vulnerability.
</p>
<h3>Affected Versions</h3>
<p>
phpMyAdmin versions 4.x (prior to 4.0.0-rc3).
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3240">CVE-2013-3240</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2013-3.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2013-3.php</link>
<title>PMASA-2013-3</title>
<dc:date>2013-04-24T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Locally Saved SQL Dump File Multiple File Extension Remote Code Execution.
</p>
<h3>Affected Versions</h3>
<p>
Versions 3.5.x and 4.0.0 (before -rc3) are affected.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3239">CVE-2013-3239</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2013-2.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2013-2.php</link>
<title>PMASA-2013-2</title>
<dc:date>2013-04-24T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Remote code execution via preg_replace().
</p>
<h3>Affected Versions</h3>
<p>
Versions 3.5.x and 4.0.0 (before -rc3) are affected.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3238">CVE-2013-3238</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2013-1.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2013-1.php</link>
<title>PMASA-2013-1</title>
<dc:date>2013-04-18T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
XSS due to unescaped HTML output in GIS visualisation page.
</p>
<h3>Affected Versions</h3>
<p>
Versions 3.5.x are affected.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1937">CVE-2013-1937</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2012-7.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2012-7.php</link>
<title>PMASA-2012-7</title>
<dc:date>2012-10-12T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Fetching the version information from a non-SSL site is vulnerable to a MITM attack.
</p>
<h3>Affected Versions</h3>
<p>
Versions 3.5.x before 3.5.3 are affected.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5368">CVE-2012-5368</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2012-6.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2012-6.php</link>
<title>PMASA-2012-6</title>
<dc:date>2012-10-12T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages.
</p>
<h3>Affected Versions</h3>
<p>
Versions 3.5.x are affected.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5339">CVE-2012-5339</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2012-5.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2012-5.php</link>
<title>PMASA-2012-5</title>
<dc:date>2012-09-25T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
One server from the SourceForge.net mirror system was distributing a phpMyAdmin kit
containing a backdoor.
</p>
<h3>Affected Versions</h3>
<p>
We currently know only about  being
affected, check if your download contains a file named
.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5159">CVE-2012-5159</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2012-4.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2012-4.php</link>
<title>PMASA-2012-4</title>
<dc:date>2012-08-16T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Multiple XSS in Table operations, Database structure, Trigger and Visualize
GIS data pages.
</p>
<h3>Affected Versions</h3>
<p>
Versions 3.4.x are affected, for issues #1 and #2.
Versions 3.5.x are affected, for all issues.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4345">CVE-2012-4345</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2012-3.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2012-3.php</link>
<title>PMASA-2012-3</title>
<dc:date>2012-08-09T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Path disclosure due to missing library.
</p>
<h3>Affected Versions</h3>
<p>
Versions 3.5.x before 3.5.2.1 are affected.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4219">CVE-2012-4219</a></p>
    </div>
]]>
</description>
</item>
</channel>
</rss>