Vulnerability record · CVE-2017-18264 · published 1 May 2018
CVE-2017-18264: Phpmyadmin vulnerability
Phpmyadmin · Phpmyadmin
An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default). This occurs because some implementations of the PHP substr function return false when given '' as the first argument.
Description
An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default). This occurs because some implementations of the PHP substr function return false when given '' as the first argument.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/97211 | Third Party AdvisoryVDB Entry |
| https://lists.debian.org/debian-lts-announce/2018/07/msg00006.html | Third Party Advisory |
| https://www.phpmyadmin.net/security/PMASA-2017-8/ | PatchVendor Advisory |
| http://www.securityfocus.com/bid/97211 | Third Party AdvisoryVDB Entry |
| https://lists.debian.org/debian-lts-announce/2018/07/msg00006.html | Third Party Advisory |
| https://www.phpmyadmin.net/security/PMASA-2017-8/ | PatchVendor Advisory |
Track CVE-2017-18264 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-18264), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.