CVE-2017-18264
01.05.2018, 17:29
An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default). This occurs because some implementations of the PHP substr function return false when given '' as the first argument.Enginsight
Vendor | Product | Version |
---|---|---|
phpmyadmin | phpmyadmin | 4.0.0 ≤ 𝑥 < 4.0.10.20 |
phpmyadmin | phpmyadmin | 4.4.0 ≤ 𝑥 ≤ 4.4.15.10 |
phpmyadmin | phpmyadmin | 4.6.0 ≤ 𝑥 ≤ 4.6.6 |
phpmyadmin | phpmyadmin | 4.7.0:beta1 |
phpmyadmin | phpmyadmin | 4.7.0:rc1 |
debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References