Information disclosure in phpMyAdmin - CVE-2012-4219

 

Information disclosure in phpMyAdmin - CVE-2012-4219

Published: August 21, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43682
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-4219
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.


Affected software

phpMyAdmin
Fedora
phpMyAdmin3
phpMyAdmin

How to mitigate CVE-2012-4219

Install update from vendor's website.

phpMyAdmin3 - update to 3.5.2.2-1.el5
phpMyAdmin - update to 3.5.2.2-1.el6

External References

Related Security Bulletins