Local file inclusion vulnerability and code execution.
In the 'relational schema' code a parameter was not sanitized before being used to concatenate a class name.
We consider this vulnerability to be critical.
An attacker must be logged in via phpMyAdmin to exploit this problem.
Versions 3.4.0 to 22.214.171.124 are affected.
Upgrade to phpMyAdmin 126.96.36.199 or apply the related patch listed below.
This issue was found by Norman Hippert from The-Wildcat.de
Assigned CVE ids: CVE-2011-2718
The following commits have been made to fix this issue:
For further information and in case of questions, please contact the phpMyAdmin team. Our website is phpmyadmin.net.