Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.
Link | Tags |
---|---|
http://www.phpmyadmin.net/home_page/relnotes.php?rel=0 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15021 | vdb entry |
http://security.gentoo.org/glsa/glsa-200402-05.xml | vendor advisory |
http://secunia.com/advisories/10769 | third party advisory |
http://www.osvdb.org/3800 | vdb entry |
http://marc.info/?l=bugtraq&m=107582619125932&w=2 | mailing list |
http://www.securityfocus.com/bid/9564 | exploit vdb entry patch vendor advisory |
http://sourceforge.net/forum/forum.php?forum_id=350228 |