CVE Vulnerabilities

CVE-2005-1392

Published: May 03, 2005 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script.

Affected Software

Name Vendor Start Version End Version
Phpmyadmin Phpmyadmin 2.6.2 (including) 2.6.2 (including)

References