CVE-2005-0459: Medium severity phpMyAdmin phpMyAdmin vulnerability
Published Feb 17, 2005
·Updated
phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to selectlang.lib.php, which reveals the path in a PHP error message.
Affected Software
36 affected components
phpMyAdmin phpMyAdmin=2.0
phpMyAdmin phpMyAdmin=2.0.1
phpMyAdmin phpMyAdmin=2.0.2
phpMyAdmin phpMyAdmin=2.0.3
phpMyAdmin phpMyAdmin=2.0.4
phpMyAdmin phpMyAdmin=2.0.5
phpMyAdmin phpMyAdmin=2.1
phpMyAdmin phpMyAdmin=2.1.1
phpMyAdmin phpMyAdmin=2.1.2
phpMyAdmin phpMyAdmin=2.2.2
phpMyAdmin phpMyAdmin=2.2.3
phpMyAdmin phpMyAdmin=2.2.4
phpMyAdmin phpMyAdmin=2.2.5
phpMyAdmin phpMyAdmin=2.2.6
phpMyAdmin phpMyAdmin=2.2_pre1
phpMyAdmin phpMyAdmin=2.2_rc1
phpMyAdmin phpMyAdmin=2.2_rc2
phpMyAdmin phpMyAdmin=2.2_rc3
phpMyAdmin phpMyAdmin=2.3.1
phpMyAdmin phpMyAdmin=2.3.2
phpMyAdmin phpMyAdmin=2.4.0
phpMyAdmin phpMyAdmin=2.5.0
phpMyAdmin phpMyAdmin=2.5.1
phpMyAdmin phpMyAdmin=2.5.2
phpMyAdmin phpMyAdmin=2.5.4
phpMyAdmin phpMyAdmin=2.5.5
phpMyAdmin phpMyAdmin=2.5.5_pl1
phpMyAdmin phpMyAdmin=2.5.5_rc1
phpMyAdmin phpMyAdmin=2.5.5_rc2
phpMyAdmin phpMyAdmin=2.5.6_rc1
phpMyAdmin phpMyAdmin=2.5.7
phpMyAdmin phpMyAdmin=2.5.7_pl1
phpMyAdmin phpMyAdmin=2.6.0_pl1
phpMyAdmin phpMyAdmin=2.6.0_pl2
phpMyAdmin phpMyAdmin=2.6.0_pl3
phpMyAdmin phpMyAdmin=2.6.2_dev
Event History
Feb 17, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0459?
CVE-2005-0459 has a severity rating of moderate, as it allows remote users to determine the server's full path.
2
How do I fix CVE-2005-0459?
To fix CVE-2005-0459, upgrade to phpMyAdmin version 2.6.2 or later to ensure proper path obfuscation.
3
What versions are affected by CVE-2005-0459?
CVE-2005-0459 affects phpMyAdmin versions up to and including 2.6.2-dev, as well as earlier versions.
4
What impact does CVE-2005-0459 have on my server?
CVE-2005-0459 may expose sensitive information regarding the file structure of your server to remote attackers.
5
Is CVE-2005-0459 a vulnerability related to PHP error messages?
Yes, CVE-2005-0459 exploits PHP error messages to reveal the full web root path.