First published: Thu Mar 26 2009(Updated: )
Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | =3.1.2 | |
phpMyAdmin phpMyAdmin | =3.1.0 | |
phpMyAdmin phpMyAdmin | =3.1.1-rc1 | |
phpMyAdmin phpMyAdmin | =3.1.1 | |
phpMyAdmin phpMyAdmin | =3.1.3-rc1 | |
phpMyAdmin phpMyAdmin | =3.1.0.0 | |
phpMyAdmin phpMyAdmin | =3.1.2-rc1 | |
phpMyAdmin phpMyAdmin | <=3.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.