5
CVSSv2

CVE-2004-0129

Published: 03/03/2004 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and previous versions allows remote malicious users to read arbitrary files via .. (dot dot) sequences in the what parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.1.1

phpmyadmin phpmyadmin 2.1.2

phpmyadmin phpmyadmin 2.2_rc1

phpmyadmin phpmyadmin 2.2_rc2

phpmyadmin phpmyadmin 2.0.5

phpmyadmin phpmyadmin 2.1

phpmyadmin phpmyadmin 2.2.6

phpmyadmin phpmyadmin 2.2_pre1

phpmyadmin phpmyadmin 2.5.0

phpmyadmin phpmyadmin 2.5.1

phpmyadmin phpmyadmin 2.5.2

phpmyadmin phpmyadmin 2.5.4

phpmyadmin phpmyadmin 2.0.2

phpmyadmin phpmyadmin 2.0.3

phpmyadmin phpmyadmin 2.0.4

phpmyadmin phpmyadmin 2.2.4

phpmyadmin phpmyadmin 2.2.5

phpmyadmin phpmyadmin 2.3.2

phpmyadmin phpmyadmin 2.4.0

phpmyadmin phpmyadmin 2.5.5_rc2

phpmyadmin phpmyadmin 2.0

phpmyadmin phpmyadmin 2.0.1

phpmyadmin phpmyadmin 2.2.2

phpmyadmin phpmyadmin 2.2.3

phpmyadmin phpmyadmin 2.2_rc3

phpmyadmin phpmyadmin 2.3.1

phpmyadmin phpmyadmin 2.5.5

phpmyadmin phpmyadmin 2.5.5_pl1

phpmyadmin phpmyadmin 2.5.5_rc1

Exploits

source: wwwsecurityfocuscom/bid/9564/info phpMyAdmin is prone to a vulnerability that may permit remote attackers to gain access to files that are readable by the hosting web server The issue is reported to exist in the 'exportphp' script and may be exploited by providing directory traversal sequences as an argument for a specific URI p ...