vulnerability

FreeBSD: VID-68611303-149e-11e7-b9bb-6805ca0b3d42: phpMyAdmin -- bypass 'no password' restriction

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Mar 29, 2017
Added
Mar 30, 2017
Modified
Dec 10, 2025

Description

The phpMyAdmin team reports: Summary Bypass $cfg['Servers'][$i]['AllowNoPassword'] Description A vulnerability was discovered where the restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions. This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default). This behavior depends on the PHP version used (it seems PHP 5 is affected, while PHP 7.0 is not). Severity We consider this vulnerability to be of moderate severity. Mitigation factor Set a password for all users.

Solution

freebsd-upgrade-package-phpmyadmin

References

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.