Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via %2e%2e%2f (encoded dot dot) sequences in the formLanguage parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Phppgadmin | Phppgadmin | 3.1 (including) | 3.1 (including) |
| Phppgadmin | Phppgadmin | 3.2 (including) | 3.2 (including) |
| Phppgadmin | Phppgadmin | 3.3 (including) | 3.3 (including) |
| Phppgadmin | Phppgadmin | 3.4 (including) | 3.4 (including) |
| Phppgadmin | Phppgadmin | 3.4.1 (including) | 3.4.1 (including) |
| Phppgadmin | Phppgadmin | 3.5.3 (including) | 3.5.3 (including) |
| Phppgadmin | Ubuntu | dapper | * |
| Phppgadmin | Ubuntu | devel | * |
| Phppgadmin | Ubuntu | edgy | * |
| Phppgadmin | Ubuntu | feisty | * |