Lucene search

K
osvGoogleOSV:GHSA-WM9C-VCV2-VPQC
HistoryMay 14, 2022 - 2:08 a.m.

phpMyAdmin full path disclosure vulnerability

2022-05-1402:08:58
Google
osv.dev
6
phpmyadmin
vulnerability
full path disclosure
sensitive information
remote attackers
array value
validation
config directory
openid identifier
error message
software

AI Score

6.3

Confidence

Low

EPSS

0.005

Percentile

77.1%

phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to obtain sensitive information via vectors involving (1) an array value to FormDisplay.php, (2) incorrect data to validate.php, (3) unexpected data to Validator.php, (4) a missing config directory during setup, or (5) an incorrect OpenID identifier data type, which reveals the full path in an error message.

AI Score

6.3

Confidence

Low

EPSS

0.005

Percentile

77.1%