exploit-db-mirror/exploits/php/webapps/23640.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

5 lines
No EOL
459 B
Text

source: http://www.securityfocus.com/bid/9564/info
phpMyAdmin is prone to a vulnerability that may permit remote attackers to gain access to files that are readable by the hosting web server. The issue is reported to exist in the 'export.php' script and may be exploited by providing directory traversal sequences as an argument for a specific URI parameter.
http://www.example.com/[phpMyAdmin_directory]/export.php?what=../../../../../../etc/passwd%00