CVE-2009-3697
phpMyAdmin 2.11.x-2.11.9.5 and 3.x-3.2.2.0 - SQL Injection via PDF Schema Generator
Title source: llmDescription
SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.
References (19)
Core 19
Core References
Issue Tracking x_refsource_confirm
http://bugs.gentoo.org/show_bug.cgi?id=288899
Various Sources x_refsource_confirm
http://typo3.org/extensions/repository/view/phpmyadmin/4.5.0/
Various Sources x_refsource_confirm
http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-015/
Vendor Advisory x_refsource_confirm
http://www.phpmyadmin.net/home_page/security/PMASA-2009-6.php
Release Notes x_refsource_confirm
http://freshmeat.net/projects/phpmyadmin/releases/306667
Vendor Advisory vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00490.html
Product x_refsource_confirm
http://dfn.dl.sourceforge.net/project/phpmyadmin/phpMyAdmin/2.11.9.6/phpMyAdmin-2.11.9.6-notes.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=528769
Mailing List mailing-list
x_refsource_mlist
http://marc.info/?l=oss-security&m=125553728512853&w=2
Release Notes x_refsource_confirm
http://freshmeat.net/projects/phpmyadmin/releases/306669
Mailing List mailing-list
x_refsource_mlist
http://marc.info/?l=oss-security&m=125561979001460&w=2
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/53741
Vendor Advisory vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00467.html
Patch, Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2899
Product x_refsource_confirm
http://dfn.dl.sourceforge.net/project/phpmyadmin/phpMyAdmin/3.2.2.1/phpMyAdmin-3.2.2.1-notes.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/36658
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/37016
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:274
Scores
EPSS
0.0258
EPSS Percentile
85.8%
Details
CWE
CWE-89
Status
published
Products (40)
phpmyadmin/phpmyadmin
2.11.0 (3 CPE variants)
phpmyadmin/phpmyadmin
2.11.0.0
phpmyadmin/phpmyadmin
2.11.0beta1
phpmyadmin/phpmyadmin
2.11.1 (2 CPE variants)
phpmyadmin/phpmyadmin
2.11.1.0
phpmyadmin/phpmyadmin
2.11.1.1
phpmyadmin/phpmyadmin
2.11.1.2
phpmyadmin/phpmyadmin
2.11.2
phpmyadmin/phpmyadmin
2.11.2.0
phpmyadmin/phpmyadmin
2.11.2.1
... and 30 more
Published
Oct 16, 2009
Tracked Since
Feb 18, 2026