Vulnerability Details CVE-2005-0459
phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.7%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2005-0459
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.0.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.0.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.0.3
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.0.4
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.0.5
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.1.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.1.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.2.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.2.3
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.2.4
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.2.5
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.2.6
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.2_pre1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.2_rc1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.2_rc2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.2_rc3
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.3.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.3.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.4.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.0
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.4
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5_pl1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5_rc1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5_rc2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.6_rc1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.7
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.7_pl1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.0_pl1
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.0_pl2
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.0_pl3
-
cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.2_dev