{"id":"GHSA-gmc7-jvv7-w245","summary":"phpMyAdmin allows remote attackers to bypass authentication and obtain sensitive information","details":"phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function.","aliases":["CVE-2010-4481"],"modified":"2025-04-12T02:27:09.301348Z","published":"2022-05-17T05:44:04Z","database_specific":{"nvd_published_at":"2010-12-17T19:00:00Z","cwe_ids":["CWE-287"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-04-12T01:46:37Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2010-4481"},{"type":"PACKAGE","url":"https://github.com/phpmyadmin/phpmyadmin"},{"type":"WEB","url":"http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin%3Ba=commitdiff%3Bh=4d9fd005671b05c4d74615d5939ed45e4d019e4c"},{"type":"WEB","url":"http://phpmyadmin.git.sourceforge.net/git/gitweb.cgi?p=phpmyadmin/phpmyadmin;a=commitdiff;h=4d9fd005671b05c4d74615d5939ed45e4d019e4c"},{"type":"WEB","url":"http://www.debian.org/security/2010/dsa-2139"},{"type":"WEB","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:000"},{"type":"WEB","url":"http://www.phpmyadmin.net/home_page/security/PMASA-2010-10.php"}],"affected":[{"package":{"name":"phpmyadmin/phpmyadmin","ecosystem":"Packagist","purl":"pkg:composer/phpmyadmin/phpmyadmin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.0-beta1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gmc7-jvv7-w245/GHSA-gmc7-jvv7-w245.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U"}]}