phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Phpmyadmin | Phpmyadmin | * | 2.11.5.1 (excluding) |
| Phpmyadmin | Ubuntu | dapper | * |
| Phpmyadmin | Ubuntu | edgy | * |
| Phpmyadmin | Ubuntu | feisty | * |
| Phpmyadmin | Ubuntu | gutsy | * |
| Phpmyadmin | Ubuntu | hardy | * |