<?xml-stylesheet type="text/css" href="http://www.phpmyadmin.net/home_page/css/feed.css"?><rss xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
<channel>
<atom:link href="http://www.phpmyadmin.net/home_page/security/index.xml" rel="self" type="application/rss+xml"></atom:link>
<title>phpMyAdmin security announcements</title>
<link>http://www.phpmyadmin.net/security/</link>
<description>phpMyAdmin security announcements</description>
<dc:language>en-us</dc:language>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:date>2010-02-09T12:22:05+00:00</dc:date>
<admin:generatorAgent rdf:resource="http://www.phpmyadmin.net"></admin:generatorAgent>
<item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2010-3.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2010-3.php</link>
<title>PMASA-2010-3</title>
<dc:date>2010-01-15T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Unsafe usage of unserialize function.
</p>
<h3>Affected Versions</h3>
<p>
For 2.11.x: versions before 2.11.10 are affected.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-4605">CVE-2009-4605</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2010-2.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2010-2.php</link>
<title>PMASA-2010-2</title>
<dc:date>2010-01-15T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Unsafe handling of temporary files
</p>
<h3>Affected Versions</h3>
<p>
For 2.11.x: versions before 2.11.10 are affected.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-7252">CVE-2008-7252</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2010-1.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2010-1.php</link>
<title>PMASA-2010-1</title>
<dc:date>2010-01-15T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Unsafe handling of temporary directory
</p>
<h3>Affected Versions</h3>
<p>
For 2.11.x: versions before 2.11.10 are affected.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-7251">CVE-2008-7251</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2009-6.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2009-6.php</link>
<title>PMASA-2009-6</title>
<dc:date>2009-10-13T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
XSS and SQL injection vulnerabilities
</p>
<h3>Affected Versions</h3>
<p>
For 2.11.x: versions before 2.11.9.6 are affected.
For 3.x: versions before 3.2.2.1 are affected.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3696">CVE-2009-3696</a></p><p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3697">CVE-2009-3697</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2009-5.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2009-5.php</link>
<title>PMASA-2009-5</title>
<dc:date>2009-06-30T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
XSS vulnerability
</p>
<h3>Affected Versions</h3>
<p>
For 2.11.x: versions are not affected.
For 3.x: All 3.x releases on which the "bookmarks" feature is active are
affected.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-2284">CVE-2009-2284</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2009-4.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2009-4.php</link>
<title>PMASA-2009-4</title>
<dc:date>2009-04-14T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Insufficient output sanitizing when generating configuration file.
</p>
<h3>Affected Versions</h3>
<p>
For 2.11.x: versions are not affected.
For 3.x: versions before 3.1.3.2.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1285">CVE-2009-1285</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2009-3.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2009-3.php</link>
<title>PMASA-2009-3</title>
<dc:date>2009-03-24T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Insufficient output sanitizing when generating configuration file.
</p>
<h3>Affected Versions</h3>
<p>
For 2.11.x: versions before 2.11.9.5.
For 3.x: versions before 3.1.3.1.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1151">CVE-2009-1151</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2009-2.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2009-2.php</link>
<title>PMASA-2009-2</title>
<dc:date>2009-03-24T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
Cross-site scripting on export page using cookies.
</p>
<h3>Affected Versions</h3>
<p>
For 2.11.x: versions before 2.11.9.5.
For 3.x: versions before 3.1.3.1.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1150">CVE-2009-1150</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2009-1.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2009-1.php</link>
<title>PMASA-2009-1</title>
<dc:date>2009-03-24T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
HTTP Response Splitting and file inclusion vulnerability.
</p>
<h3>Affected Versions</h3>
<p>
For 2.11.x: not affected as it lacks BLOB streaming support.
For 3.x: versions since 3.1.0.0 and before 3.1.3.1.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1148">CVE-2009-1148</a></p><p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1149">CVE-2009-1149</a></p>
    </div>
]]>
</description>
</item><item>
<guid>http://www.phpmyadmin.net/home_page/security/PMASA-2008-10.php</guid>
<link>http://www.phpmyadmin.net/home_page/security/PMASA-2008-10.php</link>
<title>PMASA-2008-10</title>
<dc:date>2008-12-09T00:00:00+00:00</dc:date>
<dc:creator>phpMyAdmin devel team</dc:creator>
<dc:subject>phpMyAdmin security</dc:subject>
<description>
<![CDATA[
<p>
SQL injection through XSRF on several pages
</p>
<h3>Affected Versions</h3>
<p>
For 2.11.x: versions before 2.11.9.4.
For 3.x: versions before 3.1.1.0.
</p>
<h3>CVE ID</h3>
<div>
        <p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5621">CVE-2008-5621</a></p><p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5622">CVE-2008-5622</a></p>
    </div>
]]>
</description>
</item>
</channel>
</rss>