phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=113208319104035&w=2 | mailing list |
http://securityreason.com/securityalert/185 | third party advisory |
http://www.osvdb.org/20914 | vdb entry |
http://www.osvdb.org/20912 | vdb entry |
http://securitytracker.com/id?1015213 | vdb entry |
http://www.fitsec.com/advisories/FS-05-02.txt | vendor advisory |
http://www.osvdb.org/20911 | vdb entry |
http://www.osvdb.org/20913 | vdb entry |