Candidate: CVE-2013-5000 PublicDate: 2013-07-31 13:20:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5000 http://www.phpmyadmin.net/home_page/security/PMASA-2013-12.php Description: phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files. Ubuntu-Description: Notes: Bugs: Priority: negligible Discovered-by: Assigned-to: CVSS: Patches_phpmyadmin: upstream_phpmyadmin: released (4:4.0.4.2-1) lucid_phpmyadmin: ignored (reached end-of-life) precise_phpmyadmin: ignored (reached end-of-life) precise/esm_phpmyadmin: DNE (precise was needs-triage) quantal_phpmyadmin: ignored (reached end-of-life) raring_phpmyadmin: ignored (reached end-of-life) saucy_phpmyadmin: not-affected (4:4.0.6-1) trusty_phpmyadmin: not-affected trusty/esm_phpmyadmin: not-affected utopic_phpmyadmin: not-affected vivid_phpmyadmin: not-affected vivid/stable-phone-overlay_phpmyadmin: DNE vivid/ubuntu-core_phpmyadmin: DNE wily_phpmyadmin: not-affected xenial_phpmyadmin: not-affected yakkety_phpmyadmin: not-affected zesty_phpmyadmin: not-affected devel_phpmyadmin: not-affected