First published: Mon May 02 2005(Updated: )
The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | =2.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1392 has a medium severity rating due to the exposure of sensitive information to local users.
To fix CVE-2005-1392, change the permissions of the SQL install script to restrict access to authorized users only.
CVE-2005-1392 affects phpMyAdmin version 2.6.2.
The potential consequence of CVE-2005-1392 is that local users can read the installation script and obtain the initial database password.
CVE-2005-1392 is a local vulnerability that impacts users with access to the affected system.