Vulnerability Name:

CVE-2005-0459 (CCN-19363)

Assigned:2005-02-17
Published:2005-02-17
Updated:2008-09-05
Summary:phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2005-0459

Source: CCN
Type: SECTRACK ID: 1013210
phpMyAdmin `\libraries\select_lang.lib.php` Discloses Installation Path to Remote Users

Source: SECTRACK
Type: Exploit, Vendor Advisory
1013210

Source: CCN
Type: OSVDB ID: 8505
phpMyAdmin /libraries/select_lang.lib.php Direct Request Path Disclosure

Source: CCN
Type: phpMyAdmin Web site
The phpMyAdmin Project

Source: XF
Type: UNKNOWN
phpmyadmin-path-disclosure(19363)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:phpmyadmin:phpmyadmin:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.1:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.2.5:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.2.6:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.2_pre1:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.2_rc1:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.2_rc2:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.2_rc3:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.5.4:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.5.5:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.5.5_pl1:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.5.5_rc1:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.5.5_rc2:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.5.6_rc1:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.5.7:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.5.7_pl1:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.6.0_pl1:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.6.0_pl2:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.6.0_pl3:*:*:*:*:*:*:*
  • OR cpe:/a:phpmyadmin:phpmyadmin:2.6.2_dev:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    phpmyadmin phpmyadmin 2.0
    phpmyadmin phpmyadmin 2.0.1
    phpmyadmin phpmyadmin 2.0.2
    phpmyadmin phpmyadmin 2.0.3
    phpmyadmin phpmyadmin 2.0.4
    phpmyadmin phpmyadmin 2.0.5
    phpmyadmin phpmyadmin 2.1
    phpmyadmin phpmyadmin 2.1.1
    phpmyadmin phpmyadmin 2.1.2
    phpmyadmin phpmyadmin 2.2.2
    phpmyadmin phpmyadmin 2.2.3
    phpmyadmin phpmyadmin 2.2.4
    phpmyadmin phpmyadmin 2.2.5
    phpmyadmin phpmyadmin 2.2.6
    phpmyadmin phpmyadmin 2.2_pre1
    phpmyadmin phpmyadmin 2.2_rc1
    phpmyadmin phpmyadmin 2.2_rc2
    phpmyadmin phpmyadmin 2.2_rc3
    phpmyadmin phpmyadmin 2.3.1
    phpmyadmin phpmyadmin 2.3.2
    phpmyadmin phpmyadmin 2.4.0
    phpmyadmin phpmyadmin 2.5.0
    phpmyadmin phpmyadmin 2.5.1
    phpmyadmin phpmyadmin 2.5.2
    phpmyadmin phpmyadmin 2.5.4
    phpmyadmin phpmyadmin 2.5.5
    phpmyadmin phpmyadmin 2.5.5_pl1
    phpmyadmin phpmyadmin 2.5.5_rc1
    phpmyadmin phpmyadmin 2.5.5_rc2
    phpmyadmin phpmyadmin 2.5.6_rc1
    phpmyadmin phpmyadmin 2.5.7
    phpmyadmin phpmyadmin 2.5.7_pl1
    phpmyadmin phpmyadmin 2.6.0_pl1
    phpmyadmin phpmyadmin 2.6.0_pl2
    phpmyadmin phpmyadmin 2.6.0_pl3
    phpmyadmin phpmyadmin 2.6.2_dev