Vulnerability Description
phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpmyadmin | Phpmyadmin | 2.0 |
References
- http://securitytracker.com/id?1013210ExploitVendor Advisory
- http://securitytracker.com/id?1013210ExploitVendor Advisory
FAQ
What is CVE-2005-0459?
CVE-2005-0459 is a vulnerability with a CVSS score of 5.0 (MEDIUM). phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP err...
How severe is CVE-2005-0459?
CVE-2005-0459 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0459?
Check the references section above for vendor advisories and patch information. Affected products include: Phpmyadmin Phpmyadmin.