CVE

Id
50418  
CVE No.
CVE-2011-2506  
Status
Candidate  
Description
setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array.  
Phase
Assigned (20110615)  
Votes
None (candidate not yet proposed)  
Comments