An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94521 | vdb entry third party advisory |
https://www.phpmyadmin.net/security/PMASA-2016-60 | patch vendor advisory |
https://security.gentoo.org/glsa/201701-32 | vendor advisory |
https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html | mailing list |