Information disclosure in phpMyAdmin - CVE-2013-5000

 

Information disclosure in phpMyAdmin - CVE-2013-5000

Published: July 31, 2013 / Updated: July 28, 2020


Vulnerability identifier: #VU32644
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-5000
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.


Affected software

phpMyAdmin
Gentoo Linux
Fedora
phpmyadmin (Alpine package)
phpMyAdmin
phpMyAdmin4

How to mitigate CVE-2013-5000

Install update from vendor's website.

phpMyAdmin - update to 3.5.8.2
phpmyadmin (Alpine package) - update to 4.0.4.2-r0
phpMyAdmin - update to 4.0.10.1-1.el6
phpMyAdmin4 - update to 4.0.10.3-2.el5

External References

Related Security Bulletins