Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-4219
HistoryAug 21, 2012 - 12:00 a.m.

CVE-2012-4219

2012-08-2100:00:00
ubuntu.com
ubuntu.com
10

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.004

Percentile

71.9%

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote
attackers to obtain sensitive information via a direct request, which
reveals the installation path in an error message, related to lack of
inclusion of the common.inc.php library file.

Notes

Author Note
jdstrand per upstream: For the error messages to be displayed, php.ini’s error_reporting must be set to E_ALL and display_errors must be On (these settings are not recommended on a production server in the PHP manual). only 3.5.x is affected

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.004

Percentile

71.9%