PT-2011-2794 · Php · Phpmyadmin
Mustlive
·
Published
2011-02-14
·
Updated
2022-05-17
·
CVE-2011-0986
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
phpMyAdmin versions 2.11.x through 2.11.11.1
phpMyAdmin versions 3.3.x through 3.3.9.0
Description
The issue arises from improper handling of missing files, specifically the README, ChangeLog, and LICENSE files. This allows remote attackers to determine the installation path by requesting a nonexistent file.
Recommendations
For phpMyAdmin versions 2.11.x through 2.11.11.1, update to version 2.11.11.2 to resolve the issue.
For phpMyAdmin versions 3.3.x through 3.3.9.0, update to version 3.3.9.1 to resolve the issue.
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpmyadmin