CVE-2001-0479: High severity phppgadmin phppgadmin vulnerability
Published May 24, 2001
·Updated
Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.
Affected Software
2 affected components
phpPgAdmin phpPgAdmin=2.2
phpPgAdmin phpPgAdmin=2.2.1
Remediation
Patch Available
Event History
May 24, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is CVE-2001-0479?
CVE-2001-0479 is a directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier, allowing remote attackers to execute arbitrary code.
2
What versions of phpPgAdmin are affected by CVE-2001-0479?
phpPgAdmin versions 2.2 and 2.2.1 are affected by CVE-2001-0479.
3
How do I fix CVE-2001-0479?
To fix CVE-2001-0479, upgrade phpPgAdmin to a version that is newer than 2.2.1.
4
What types of attacks can CVE-2001-0479 enable?
CVE-2001-0479 can enable remote code execution attacks due to improper validation of input parameters.
5
Is there a workaround for CVE-2001-0479?
A workaround for CVE-2001-0479 includes restricting access to the vulnerable scripts until a patch is applied.