CVE-2012-1902

Priority
Low
Description
show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a
configuration file does not exist, allows remote attackers to obtain
sensitive information via a direct request, which reveals the installation
path in an error message about this missing file.
References
Bugs
tyhicks> Versions 3.4.x are affected.
Package
Upstream:released (4:3.4.10.2-1)
Ubuntu 10.04 LTS (Lucid Lynx):not-affected
Ubuntu 12.04 LTS (Precise Pangolin):needed
Ubuntu 12.10 (Quantal Quetzal):needed
Ubuntu 13.04 (Raring Ringtail):ignored (reached end-of-life)
Ubuntu 13.10 (Saucy Salamander):needed
Ubuntu 14.04 LTS (Trusty Tahr):needed
More Information

Valid XHTML 1.0 Strict

Updated: 2014-01-27 19:15:25 UTC (commit 7690)