CVE-2006-6373: Medium severity phpmyadmin phpmyadmin vulnerability
Published Dec 7, 2006
·Updated
PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the path in an error message.
Affected Software
1 affected component
phpMyAdmin phpMyAdmin=2.7.0_pl2
Event History
Dec 7, 2006
CVE Published
05:28 PM
Data Sourced
via NVD·05:28 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6373?
CVE-2006-6373 has a moderate severity rating as it exposes sensitive information via error messages.
2
How do I fix CVE-2006-6373?
To fix CVE-2006-6373, update phpMyAdmin to a version that is not affected, preferably 2.7.0-pl3 or later.
3
What kind of information does CVE-2006-6373 expose?
CVE-2006-6373 can expose the file path of the phpMyAdmin installation in error messages.
4
Is CVE-2006-6373 an authentication-related vulnerability?
No, CVE-2006-6373 does not require authentication to exploit, making it accessible to remote attackers.
5
What versions of phpMyAdmin are affected by CVE-2006-6373?
CVE-2006-6373 specifically affects phpMyAdmin version 2.7.0-pl2.