FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0129

This CVE name corresponds to:

Entered Topic
2004-02-22 file disclosure in phpMyAdmin

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type CVE Entry
Name CVE-2004-0129

Description

Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.

References

Source Reference
BUGTRAQ 20040203 Arbitrary File Disclosure Vulnerability in phpMyAdmin 2.5.5-pl1 and prior
CONFIRM http://sourceforge.net/forum/forum.php?forum_id=350228
CONFIRM http://www.phpmyadmin.net/home_page/relnotes.php?rel=0
GENTOO GLSA-200402-05
BID 9564
OSVDB 3800
SECUNIA 10769
XF phpmyadmin-dotdot-directory-traversal(15021)