phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to Error.class.php and Error_Handler.class.php.
| Software | From | Fixed in |
|---|---|---|
phpmyadmin / phpmyadmin
|
4.0.0 | 4.0.0.x |
phpmyadmin / phpmyadmin
|
4.0.3 | 4.0.3.x |
phpmyadmin / phpmyadmin
|
4.0.2 | 4.0.2.x |
phpmyadmin / phpmyadmin
|
4.0.4.1 | 4.0.4.1.x |
phpmyadmin / phpmyadmin
|
4.0.1 | 4.0.1.x |
phpmyadmin / phpmyadmin
|
4.0.0-rc2 | 4.0.0-rc2.x |
phpmyadmin / phpmyadmin
|
4.0.4 | 4.0.4.x |
phpmyadmin / phpmyadmin
|
4.0.0-rc3 | 4.0.0-rc3.x |