First published: Mon Oct 06 2008(Updated: )
Directory traversal vulnerability in EKINdesigns MySQL Quick Admin 1.5.5 allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the lang parameter to actions.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL | =1.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4454 is considered to have a medium severity due to its ability to allow remote attackers to potentially access sensitive files.
To fix CVE-2008-4454, upgrade to a patched version of MySQL Quick Admin that addresses the directory traversal vulnerability.
CVE-2008-4454 specifically affects MySQL Quick Admin version 1.5.5.
CVE-2008-4454 is a directory traversal vulnerability that allows unauthorized file access by manipulating input parameters.
CVE-2008-4454 may allow remote attackers to read sensitive files, which could lead to further exploitation, but it does not directly lead to remote code execution.