Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via %2e%2e%2f (encoded dot dot) sequences in the formLanguage parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phppgadmin | Phppgadmin | 3.1 (including) | 3.1 (including) |
Phppgadmin | Phppgadmin | 3.2 (including) | 3.2 (including) |
Phppgadmin | Phppgadmin | 3.3 (including) | 3.3 (including) |
Phppgadmin | Phppgadmin | 3.4 (including) | 3.4 (including) |
Phppgadmin | Phppgadmin | 3.4.1 (including) | 3.4.1 (including) |
Phppgadmin | Phppgadmin | 3.5.3 (including) | 3.5.3 (including) |
Phppgadmin | Ubuntu | dapper | * |
Phppgadmin | Ubuntu | devel | * |
Phppgadmin | Ubuntu | edgy | * |
Phppgadmin | Ubuntu | feisty | * |