phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpmyadmin | Phpmyadmin | * | 2.11.5.1 (excluding) |
Phpmyadmin | Ubuntu | dapper | * |
Phpmyadmin | Ubuntu | edgy | * |
Phpmyadmin | Ubuntu | feisty | * |
Phpmyadmin | Ubuntu | gutsy | * |
Phpmyadmin | Ubuntu | hardy | * |