CVE-2012-4219
published 2012-08-21CVE-2012-4219: show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the…
PriorityP411medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.30%
81.4th percentile
show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:4.0.1-1 (bookworm) | phpmyadmin 4:4.0.1-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.0.1-1 | 4:4.0.1-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.0.1-1 | 4:4.0.1-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.0.1-1 | 4:4.0.1-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.0.1-1 | 4:4.0.1-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2012-4219: phpmyadmin - show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attacker...
vendor_debian·2012·CVSS 5.0
CVE-2012-4219 [MEDIUM] CVE-2012-4219: phpmyadmin - show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attacker...
show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.
Scope: local
bookworm: resolved (fixed in 4:4.0.1-1)
bullseye: resolved (fixed in 4:4.0.1-1)
forky: resolved (fixed in 4:4.0.1-1)
sid: resolved (fixed in 4:4.0.1-1)
trixie: resolved (fixed in 4:4.0.1-1)
GHSA
GHSA-8vv2-p6c9-46c2: show_config_errors
ghsa_unreviewed·2022-05-17
CVE-2012-4219 [MEDIUM] CWE-200 GHSA-8vv2-p6c9-46c2: show_config_errors
show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.
OSV
CVE-2012-4219: show_config_errors
osv·2012-08-21·CVSS 5.0
CVE-2012-4219 [MEDIUM] CVE-2012-4219: show_config_errors
show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.
No detection rules found.
No public exploits indexed.
http://www.phpmyadmin.net/home_page/security/PMASA-2012-3.phphttps://github.com/phpmyadmin/phpmyadmin/commit/0f0c2f1e2b3ece41cc1bb99a9931c8fcc7c917bchttps://hermes.opensuse.org/messages/15513071http://www.phpmyadmin.net/home_page/security/PMASA-2012-3.phphttps://github.com/phpmyadmin/phpmyadmin/commit/0f0c2f1e2b3ece41cc1bb99a9931c8fcc7c917bchttps://hermes.opensuse.org/messages/15513071
2012-08-21
Published