CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
Percentile
71.9%
Announcement-ID: PMASA-2012-3
Date: 2012-08-09
Path disclosure due to missing library.
The show_config_errors.php script does not include a library, so an error message shows the full path of this file, leading to possible further attacks.
We consider this vulnerability to be non critical.
For the error messages to be displayed, php.iniâs error_reporting must be set to E_ALL and display_errors must be On (these settings are not recommended on a production server in the PHP manual).
Versions 3.5.x before 3.5.2.1 are affected.
Upgrade to phpMyAdmin 3.5.2.1 or newer or apply the related patch listed below.
Thanks to Edgar Galan for reporting this issue.
Assigned CVE ids: CVE-2012-4219
The following commits have been made to fix this issue:
For further information and in case of questions, please contact the phpMyAdmin team. Our website is phpmyadmin.net.