CVE-2005-0544: SQL Injection
phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) selecttheme.lib.php, (4) selectlang.lib.php, (5) relationcleanup.lib.php, (6) headermetastyle.inc.php, (7) getforeign.lib.php, (8) displaytbllinks.lib.php, (9) displayexport.lib.php, (10) dbtableexists.lib.php, (11) charsetconversion.lib.php, (12) ufpdf.php, (13) mysqli.dbi.lib.php, (14) setup.php, or (15) cookie.auth.lib.php, which reveals the path in a PHP error message.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0544?
CVE-2005-0544 is classified as a low severity vulnerability.
How do I fix CVE-2005-0544?
To fix CVE-2005-0544, upgrade phpMyAdmin to version 2.6.2 or later.
What software versions are affected by CVE-2005-0544?
CVE-2005-0544 affects phpMyAdmin version 2.6.1.
What type of vulnerability is CVE-2005-0544?
CVE-2005-0544 is a path disclosure vulnerability.
Can CVE-2005-0544 be exploited remotely?
Yes, CVE-2005-0544 can be exploited by remote attackers.