libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade phpmyadmin | Jul 30, 2024 | Sep 18, 2008 |
| Freebsd | — | Upgrade phpMyAdmin | Dec 10, 2025 | Sep 17, 2008 |
| Gentoo Linux | — | Upgrade dev-db/phpmyadmin. | Oct 30, 2017 | Sep 18, 2008 |
| Phpmyadmin | — | Upgrade phpMyAdmin to the latest version | May 4, 2017 | Sep 18, 2008 |
| Suse | — | Upgrade phpmyadmin | Feb 17, 2015 | Sep 18, 2008 |
| Ubuntu | — | Upgrade phpmyadmin | Nov 19, 2024 | Sep 18, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub