Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2008-5587
HistoryDec 16, 2008 - 7:07 p.m.

CVE-2008-5587

2008-12-1619:07:31
Debian Security Bug Tracker
security-tracker.debian.org
12

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

0.024 Low

EPSS

Percentile

90.0%

Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a … (dot dot) in the _language parameter to index.php.

OSVersionArchitecturePackageVersionFilename
Debian999allphppgadmin< 4.2.1-1.1phppgadmin_4.2.1-1.1_all.deb
Debian13allphppgadmin< 4.2.1-1.1phppgadmin_4.2.1-1.1_all.deb

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

0.024 Low

EPSS

Percentile

90.0%