Vulnerability Name: | CVE-2012-4219 (CCN-77824) | ||||||||||||||||||||
Assigned: | 2012-08-17 | ||||||||||||||||||||
Published: | 2012-08-17 | ||||||||||||||||||||
Updated: | 2012-09-07 | ||||||||||||||||||||
Summary: | show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file. | ||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-4219 Source: CCN Type: OSVDB ID: 84587 phpMyAdmin show_config_errors.php Error Message Path Disclosure (2012-4219) Source: CCN Type: phpMyAdmin Web Site phpMyAdmin Source: CCN Type: PMASA-2012-3 Path disclosure due to missing library. Source: CONFIRM Type: Vendor Advisory http://www.phpmyadmin.net/home_page/security/PMASA-2012-3.php Source: CCN Type: BID-55057 phpMyAdmin CVE-2012-4219 'show_config_errors.php' Full Path Information Disclosure Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 849007 CVE-2012-4219 phpMyAdmin: show_config_errors.php path disclosure flaw (PMASA-2012-3) Source: XF Type: UNKNOWN phpmyadmin-errorreporting-path-disclosure(77824) Source: CONFIRM Type: Exploit https://github.com/phpmyadmin/phpmyadmin/commit/0f0c2f1e2b3ece41cc1bb99a9931c8fcc7c917bc Source: SUSE Type: UNKNOWN openSUSE-SU-2012:1062 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |