Description
libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vectors.
References (9)
Core 9
Core References
Product x_refsource_confirm
http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin?view=rev&revision=11528
Product x_refsource_confirm
http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/QA_2_11/phpMyAdmin/libraries/File.class.php?r1=11528&r2=11527&pathrev=11528
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/38211
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/39503
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0910
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2010/dsa-2034
Vendor Advisory x_refsource_confirm
http://www.phpmyadmin.net/home_page/security/PMASA-2010-2.php
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/37826
Scores
EPSS
0.0296
EPSS Percentile
86.7%
Details
CWE
CWE-310
Status
published
Products (39)
phpmyadmin/phpmyadmin
2.11.0 (3 CPE variants)
phpmyadmin/phpmyadmin
2.11.0.0
phpmyadmin/phpmyadmin
2.11.0beta1
phpmyadmin/phpmyadmin
2.11.0rc1
phpmyadmin/phpmyadmin
2.11.1 (2 CPE variants)
phpmyadmin/phpmyadmin
2.11.1.0
phpmyadmin/phpmyadmin
2.11.1.1
phpmyadmin/phpmyadmin
2.11.1.2
phpmyadmin/phpmyadmin
2.11.1rc1
phpmyadmin/phpmyadmin
2.11.2
... and 29 more
Published
Jan 19, 2010
Tracked Since
Feb 18, 2026