CVE-2008-5587
medium · 4.3A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the _language parameter to index.php.
4.3
CVSS
12.9%
EPSS (exploit prob.)
96th
EPSS percentile
2008-12-16
Published
AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| phppgadmin | phppgadmin | <= 4.2.1 |
| phppgadmin | phppgadmin | 2.2 |
| phppgadmin | phppgadmin | 2.2.1 |
| phppgadmin | phppgadmin | 3.1 |
| phppgadmin | phppgadmin | 3.4.1 |
| phppgadmin | phppgadmin | 3.5 |
| phppgadmin | phppgadmin | 3.5.2 |
| phppgadmin | phppgadmin | 3.5.3 |
| phppgadmin | phppgadmin | 4.1.1 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
- http://lists.opensuse.org/opensuse-updates/2012-04/msg00033.html
- http://secunia.com/advisories/33014
- http://secunia.com/advisories/33263
- http://securityreason.com/securityalert/4737
- http://www.debian.org/security/2008/dsa-1693
- http://www.securityfocus.com/bid/32670
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47140
- https://www.exploit-db.com/exploits/7363
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
- http://lists.opensuse.org/opensuse-updates/2012-04/msg00033.html
- http://secunia.com/advisories/33014
- http://secunia.com/advisories/33263
- http://securityreason.com/securityalert/4737
- http://www.debian.org/security/2008/dsa-1693
- http://www.securityfocus.com/bid/32670
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47140
- https://www.exploit-db.com/exploits/7363
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-5587