Skip to navigation

CVE Database

CVE-2012-4219

Impact: Low
Public: 2012-08-09
Bugzilla: 849007: CVE-2012-4219 phpMyAdmin: show_config_errors.php path disclosure flaw (PMASA-2012-3)

Details

The MITRE CVE dictionary describes this issue as:

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.

Find out more about CVE-2012-4219 from the MITRE CVE dictionary and NIST NVD.

CVSS v2 metrics

NOTE: The following CVSS v2 metrics and score provided are preliminary and subject to review.

Base Score: 2.6
Base Metrics: AV:N/AC:H/Au:N/C:P/I:N/A:N
Access Vector: Network
Access Complexity: High
Authentication: None
Confidentiality Impact: Partial
Integrity Impact: None
Availability Impact: None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat security errata

Platform Errata Release Date

External References

http://www.phpmyadmin.net/home_page/security/PMASA-2012-3.php

This page is generated automatically and has not been checked for errors or omissions.

For clarification or corrections please contact the Red Hat Security Response Team.