20040203 Arbitrary File Disclosure Vulnerability in phpMyAdmin 2.5.5-pl1 and priormailing list
http://marc.info/?l=bugtraq&m=107582619125932&w=2 CVE-2004-0129
phpMyAdmin 2.x - 'Export.php' File Disclosure
Record summary
CVE-2004-0129 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBphpMyAdmin 2.x - 'Export.php' File DisclosureExploitDB exploitby Cedric CochinNot analyzed1 file
References
910769Third-party advisory
http://secunia.com/advisories/10769 GLSA-200402-05Vendor advisory
http://security.gentoo.org/glsa/glsa-200402-05.xml sourceforge.netConfirmation
http://sourceforge.net/forum/forum.php?forum_id=350228 3800vdb entry
http://www.osvdb.org/3800 phpmyadmin.netConfirmation
http://www.phpmyadmin.net/home_page/relnotes.php?rel=0 9564vdb entry
http://www.securityfocus.com/bid/9564 phpmyadmin-dotdot-directory-traversal(15021)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15021 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0129