CVE-2012-1902
published 2012-04-06CVE-2012-1902: show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information…
PriorityP411medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.14%
80.0th percentile
show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:3.4.10.2-1 (bookworm) | phpmyadmin 4:3.4.10.2-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.10.2-1 | 4:3.4.10.2-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.10.2-1 | 4:3.4.10.2-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.10.2-1 | 4:3.4.10.2-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:3.4.10.2-1 | 4:3.4.10.2-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4953-8rw3-w7m5: show_config_errors
ghsa_unreviewed·2022-05-14
CVE-2012-1902 [MEDIUM] CWE-200 GHSA-4953-8rw3-w7m5: show_config_errors
show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.
OSV
CVE-2012-1902: show_config_errors
osv·2012-04-06·CVSS 4.3
CVE-2012-1902 [MEDIUM] CVE-2012-1902: show_config_errors
show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.
Debian
CVE-2012-1902: phpmyadmin - show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration...
vendor_debian·2012·CVSS 4.3
CVE-2012-1902 [MEDIUM] CVE-2012-1902: phpmyadmin - show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration...
show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.
Scope: local
bookworm: resolved (fixed in 4:3.4.10.2-1)
bullseye: resolved (fixed in 4:3.4.10.2-1)
forky: resolved (fixed in 4:3.4.10.2-1)
sid: resolved (fixed in 4:3.4.10.2-1)
trixie: resolved (fixed in 4:3.4.10.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2) [epel-5]
bugzilla·2012-04-02·CVSS 4.3
CVE-2012-1902 [MEDIUM] CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2) [epel-5]
CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2) [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs
Bugzilla
CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2)
bugzilla·2012-04-02·CVSS 4.3
CVE-2012-1902 [MEDIUM] CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2)
CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2)
It was reported that phpMyAdmin 3.4.x suffers from a path disclosure flaw due to the missing verification of a file's presence. The show_config_errors.php script did not first check for the existence of the configuration file, so if the configuration file did not exist, it would display an error message with the full path of this file.
For the error message to be displayed, the server must be configured to have error_reporting set to E_ALL and display_errors to On in php.ini; these settings are not recommended for a production PHP server.
This has been corrected in 3.4.10.2 via the following commit:
https://github.com/phpmyadmin/phpmyadmin/commit/c51817d3b8cb05ff54dca9373c0667e29b8498d4
External References:
http://www.php
Bugzilla
CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2) [fedora-all]
bugzilla·2012-04-02·CVSS 4.3
CVE-2012-1902 [MEDIUM] CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2) [fedora-all]
CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&
Bugzilla
CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2) [epel-6]
bugzilla·2012-04-02·CVSS 4.3
CVE-2012-1902 [MEDIUM] CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2) [epel-6]
CVE-2012-1902 phpMyAdmin: path disclosure flaw (PMASA-2012-2) [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079435.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/079475.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/079566.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:050http://www.phpmyadmin.net/home_page/security/PMASA-2012-2.phphttp://www.securityfocus.com/bid/52858https://exchange.xforce.ibmcloud.com/vulnerabilities/74608https://github.com/phpmyadmin/phpmyadmin/commit/c51817d3b8cb05ff54dca9373c0667e29b8498d4http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079435.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/079475.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/079566.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:050http://www.phpmyadmin.net/home_page/security/PMASA-2012-2.phphttp://www.securityfocus.com/bid/52858https://exchange.xforce.ibmcloud.com/vulnerabilities/74608https://github.com/phpmyadmin/phpmyadmin/commit/c51817d3b8cb05ff54dca9373c0667e29b8498d4
2012-04-06
Published