phpMyAdmin CVE-2013-4998 Multiple Unspecified Full Path Information Disclosure Vulnerabilities
BID:61513
Info
phpMyAdmin CVE-2013-4998 Multiple Unspecified Full Path Information Disclosure Vulnerabilities
| Bugtraq ID: | 61513 |
| Class: | Unknown |
| CVE: |
CVE-2013-4998 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2013 12:00AM |
| Updated: | Apr 13 2015 09:42PM |
| Credit: | Emanuel Bronshtein |
| Vulnerable: |
phpMyAdmin phpMyAdmin 4.0.4 phpMyAdmin phpMyAdmin 4.0.3 phpMyAdmin phpMyAdmin 4.0.2 phpMyAdmin phpMyAdmin 4.0.1 phpMyAdmin phpMyAdmin 4.0 phpMyAdmin phpMyAdmin 3.5.2 phpMyAdmin phpMyAdmin 3.5.1 phpMyAdmin phpMyAdmin 4.0.4.1 phpMyAdmin phpMyAdmin 4.0.0-rc3 phpMyAdmin phpMyAdmin 4.0.0-rc2 phpMyAdmin phpMyAdmin 3.5.8.1 phpMyAdmin phpMyAdmin 3.5.8 phpMyAdmin phpMyAdmin 3.5.7 phpMyAdmin phpMyAdmin 3.5.3 phpMyAdmin phpMyAdmin 3.5.2-rc1 phpMyAdmin phpMyAdmin 3.5.1-rc1 phpMyAdmin phpMyAdmin 3.5.0 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux |
| Not Vulnerable: |
phpMyAdmin phpMyAdmin 4.0.4.2 phpMyAdmin phpMyAdmin 3.5.8.2 |
Discussion
phpMyAdmin CVE-2013-4998 Multiple Unspecified Full Path Information Disclosure Vulnerabilities
phpMyAdmin is prone to multiple unspecified information-disclosure vulnerabilities.
Remote attackers can exploit these issues to obtain sensitive information that may lead to further attacks.
phpMyAdmin versions 3.5.x prior to 3.5.8.2 and 4.0.x prior to 4.0.4.2 are vulnerable.
phpMyAdmin is prone to multiple unspecified information-disclosure vulnerabilities.
Remote attackers can exploit these issues to obtain sensitive information that may lead to further attacks.
phpMyAdmin versions 3.5.x prior to 3.5.8.2 and 4.0.x prior to 4.0.4.2 are vulnerable.
Exploit / POC
phpMyAdmin CVE-2013-4998 Multiple Unspecified Full Path Information Disclosure Vulnerabilities
Attackers can exploit these issues using a browser or readily available tools.
Attackers can exploit these issues using a browser or readily available tools.
Solution / Fix
phpMyAdmin CVE-2013-4998 Multiple Unspecified Full Path Information Disclosure Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva phpmyadmin-3.5.8.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva phpmyadmin-3.5.8.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
Mandriva Business Server 1 X86 64
-
Mandriva phpmyadmin-3.5.8.2-0.1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/
References
phpMyAdmin CVE-2013-4998 Multiple Unspecified Full Path Information Disclosure Vulnerabilities
References:
References:
- phpMyAdmin Homepage (phpMyAdmin)