CVE-2004-0129
phpMyAdmin <= 2.5.5 - Directory Traversal via Export Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-0129. PoCs published by Cedric Cochin.
AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in phpMyAdmin's 'export.php' script to read arbitrary files accessible by the web server. The attack involves appending traversal sequences to the 'what' parameter to access files like '/etc/passwd'.
Description
Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.
Exploits (1)
This exploit leverages a directory traversal vulnerability in phpMyAdmin's 'export.php' script to read arbitrary files accessible by the web server. The attack involves appending traversal sequences to the 'what' parameter to access files like '/etc/passwd'.