phpMyAdmin 'show_config_errors.php' Full Path Information Disclosure Vulnerability
BID:52858
Info
phpMyAdmin 'show_config_errors.php' Full Path Information Disclosure Vulnerability
| Bugtraq ID: | 52858 |
| Class: | Unknown |
| CVE: |
CVE-2012-1902 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2012 12:00AM |
| Updated: | Apr 13 2015 09:25PM |
| Credit: | Mateusz Goik |
| Vulnerable: |
phpMyAdmin phpMyAdmin 3.4.10 1 phpMyAdmin phpMyAdmin 3.4.10 phpMyAdmin phpMyAdmin 3.4.9 phpMyAdmin phpMyAdmin 3.4.8 phpMyAdmin phpMyAdmin 3.4.6 phpMyAdmin phpMyAdmin 3.4.5 phpMyAdmin phpMyAdmin 3.4.3 phpMyAdmin phpMyAdmin 3.4.5 phpMyAdmin phpMyAdmin 3.4.4 phpMyAdmin phpMyAdmin 3.4.3.2 phpMyAdmin phpMyAdmin 3.4.3.1 phpMyAdmin phpMyAdmin 3.4.1 phpMyAdmin phpMyAdmin 3.4.0-beta1 phpMyAdmin phpMyAdmin 3.4.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 |
| Not Vulnerable: |
phpMyAdmin phpMyAdmin 3.4.10.2 |
Discussion
phpMyAdmin 'show_config_errors.php' Full Path Information Disclosure Vulnerability
phpMyAdmin is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
phpMyAdmin versions prior to 3.4.10.2 are vulnerable.
phpMyAdmin is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
phpMyAdmin versions prior to 3.4.10.2 are vulnerable.
Exploit / POC
phpMyAdmin 'show_config_errors.php' Full Path Information Disclosure Vulnerability
Attackers can exploit this issue using a browser or readily available tools.
Attackers can exploit this issue using a browser or readily available tools.
Solution / Fix
phpMyAdmin 'show_config_errors.php' Full Path Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva phpmyadmin-3.4.10.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva phpmyadmin-3.4.10.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
References
phpMyAdmin 'show_config_errors.php' Full Path Information Disclosure Vulnerability
References:
References:
- phpMyAdmin Homepage (phpMyAdmin)
- PMASA-2012-2 (phpMyAdmin )