Description
Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.
Remediation
References
Related Vulnerabilities
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-3379)
WordPress Plugin FoxyPress 'uploadify.php' Arbitrary File Upload (0.4.2.1)
MySQL CVE-2016-0606 Vulnerability (CVE-2016-0606)
WordPress Plugin simpleSAMLphp Authentication Cross-Site Scripting (0.7.0)
WordPress Plugin underConstruction Cross-Site Request Forgery (1.08)