Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the _language parameter to index.php.
| Software | From | Fixed in |
|---|---|---|
| phppgadmin / phppgadmin | - | 4.2.1.x |
| phppgadmin / phppgadmin | 3.5.3 | 3.5.3.x |
| phppgadmin / phppgadmin | 2.2 | 2.2.x |
| phppgadmin / phppgadmin | 3.1 | 3.1.x |
| phppgadmin / phppgadmin | 3.4.1 | 3.4.1.x |
| phppgadmin / phppgadmin | 4.1.1 | 4.1.1.x |
| phppgadmin / phppgadmin | 2.2.1 | 2.2.1.x |
| phppgadmin / phppgadmin | 3.5 | 3.5.x |
| phppgadmin / phppgadmin | 3.5.2 | 3.5.2.x |