CVE
- Id
- 3295
- CVE No.
- CVE-2001-0478
- Status
- Candidate
- Description
- Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.
- Phase
- Proposed (20010524)
- Votes
- ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Renaud, Wall, Ziese | REVIEWING(1) Williams
- Comments
- Frech> XF:phpmyadmin-sqlphp-include-file(6483) | Christey> Double-check the version number - is it 2.1.0 or 2.2.0? | CONFIRM:http://phpmyadmin.sourceforge.net/ChangeLog.txt | Item 2001-04-28 says "applied security patch from [Secure | Reality] | The patch implies that tbl_replace.php was also affected.