5
CVSSv2

CVE-2005-0459

Published: 02/05/2005 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote malicious users to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 2.1.1

phpmyadmin phpmyadmin 2.2.4

phpmyadmin phpmyadmin 2.1.2

phpmyadmin phpmyadmin 2.2 pre1

phpmyadmin phpmyadmin 2.5.0

phpmyadmin phpmyadmin 2.0.4

phpmyadmin phpmyadmin 2.3.1

phpmyadmin phpmyadmin 2.0.2

phpmyadmin phpmyadmin 2.5.5 rc1

phpmyadmin phpmyadmin 2.6.0 pl3

phpmyadmin phpmyadmin 2.5.7 pl1

phpmyadmin phpmyadmin 2.4.0

phpmyadmin phpmyadmin 2.5.5

phpmyadmin phpmyadmin 2.5.7

phpmyadmin phpmyadmin 2.5.6 rc1

phpmyadmin phpmyadmin 2.0.3

phpmyadmin phpmyadmin 2.2.6

phpmyadmin phpmyadmin 2.6.2 dev

phpmyadmin phpmyadmin 2.6.0 pl1

phpmyadmin phpmyadmin 2.5.2

phpmyadmin phpmyadmin 2.1

phpmyadmin phpmyadmin 2.0.1

phpmyadmin phpmyadmin 2.5.1

phpmyadmin phpmyadmin 2.6.0 pl2

phpmyadmin phpmyadmin 2.2 rc2

phpmyadmin phpmyadmin 2.3.2

phpmyadmin phpmyadmin 2.5.4

phpmyadmin phpmyadmin 2.2.5

phpmyadmin phpmyadmin 2.2 rc3

phpmyadmin phpmyadmin 2.2.2

phpmyadmin phpmyadmin 2.2.3

phpmyadmin phpmyadmin 2.5.5 rc2

phpmyadmin phpmyadmin 2.2 rc1

phpmyadmin phpmyadmin 2.0

phpmyadmin phpmyadmin 2.5.5 pl1

phpmyadmin phpmyadmin 2.0.5