phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.
SuSE Linux 8.2 for IA32 SuSE Linux 9.0 for AMD64 SuSE Linux 9.0 for IA32 SUSE LINUX 9.1 for IA32 SUSE LINUX 9.1 for x86-64 SUSE LINUX 9.2 SUSE LINUX 9.3