CVE-2014-8961Path Traversal in Phpmyadmin

CWE-22Path Traversal7 documents5 sources
Severity
4.0MEDIUMNVD
EPSS
1.4%
top 19.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30
Latest updateMay 14

Description

Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages4 packages

debiandebian/phpmyadmin< phpmyadmin 4:4.2.12-1 (bookworm)
Debianphpmyadmin/phpmyadmin< 4:4.2.12-1+3
NVDphpmyadmin/phpmyadmin35 versions+34
NVDopensuse/opensuse12.3, 13.1, 13.2+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mvfx-p4hj-mppj: Directory traversal vulnerability in libraries/error_report2022-05-14
OSV
CVE-2014-8961: Directory traversal vulnerability in libraries/error_report2014-11-30

📋Vendor Advisories

1
Debian
CVE-2014-8961: phpmyadmin - Directory traversal vulnerability in libraries/error_report.lib.php in the error...2014

💬Community

3
Bugzilla
CVE-2014-8961 phpMyAdmin: leakage of line count of an arbitrary file (PMASA-2014-16) [fedora-all]2014-11-21
Bugzilla
CVE-2014-8961 phpMyAdmin: leakage of line count of an arbitrary file (PMASA-2014-16)2014-11-21
Bugzilla
CVE-2014-8961 phpMyAdmin: leakage of line count of an arbitrary file (PMASA-2014-16) [epel-7]2014-11-21