phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpmyadmin | Phpmyadmin | * | 2.9.1 (including) |
Phpmyadmin | Phpmyadmin | 2.9.0 (including) | 2.9.0 (including) |
Phpmyadmin | Phpmyadmin | 2.9.0.1 (including) | 2.9.0.1 (including) |
Phpmyadmin | Phpmyadmin | 2.9.0.2 (including) | 2.9.0.2 (including) |
Phpmyadmin | Phpmyadmin | 2.9.0.3 (including) | 2.9.0.3 (including) |
Phpmyadmin | Phpmyadmin | 2.9.0_beta1 (including) | 2.9.0_beta1 (including) |
Phpmyadmin | Phpmyadmin | 2.9.0_rc1 (including) | 2.9.0_rc1 (including) |
Phpmyadmin | Phpmyadmin | 2.9.1_rc1 (including) | 2.9.1_rc1 (including) |
Phpmyadmin | Phpmyadmin | 2.9.1_rc2 (including) | 2.9.1_rc2 (including) |
Phpmyadmin | Ubuntu | dapper | * |
Phpmyadmin | Ubuntu | edgy | * |
Phpmyadmin | Ubuntu | upstream | * |