First published: Thu Dec 07 2006(Updated: )
PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the path in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PhpMyAdmin | =2.7.0_pl2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6373 has a moderate severity rating as it exposes sensitive information via error messages.
To fix CVE-2006-6373, update phpMyAdmin to a version that is not affected, preferably 2.7.0-pl3 or later.
CVE-2006-6373 can expose the file path of the phpMyAdmin installation in error messages.
No, CVE-2006-6373 does not require authentication to exploit, making it accessible to remote attackers.
CVE-2006-6373 specifically affects phpMyAdmin version 2.7.0-pl2.