PT-2011-2794 · Php · Phpmyadmin
Mustlive
·
Publicado
2011-02-14
·
Atualizado
2022-05-17
·
CVE-2011-0986
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
phpMyAdmin versions 2.11.x through 2.11.11.1
phpMyAdmin versions 3.3.x through 3.3.9.0
Description
The issue arises from improper handling of missing files, specifically the README, ChangeLog, and LICENSE files. This allows remote attackers to determine the installation path by requesting a nonexistent file.
Recommendations
For phpMyAdmin versions 2.11.x through 2.11.11.1, update to version 2.11.11.2 to resolve the issue.
For phpMyAdmin versions 3.3.x through 3.3.9.0, update to version 3.3.9.1 to resolve the issue.
Correção
RCE
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phpmyadmin