CVE-2012-1902Sensitive Information Exposure in Phpmyadmin

Severity
4.3MEDIUMNVD
EPSS
0.5%
top 35.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 6
Latest updateMay 14

Description

show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/phpmyadmin< phpmyadmin 4:3.4.10.2-1 (bookworm)
Debianphpmyadmin/phpmyadmin< 4:3.4.10.2-1+3
NVDphpmyadmin/phpmyadmin15 versions+14

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4953-8rw3-w7m5: show_config_errors2022-05-14
OSV
CVE-2012-1902: show_config_errors2012-04-06

📋Vendor Advisories

1
Debian
CVE-2012-1902: phpmyadmin - show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration...2012

💬Community

4
Bugzilla
CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2) [epel-5]2012-04-02
Bugzilla
CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2)2012-04-02
Bugzilla
CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2) [fedora-all]2012-04-02
Bugzilla
CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2) [epel-6]2012-04-02