LWN.net Logo

phpMyAdmin: insecure SQL script installation

Package(s):phpMyAdmin CVE #(s):
Created:May 2, 2005 Updated:May 3, 2005
Description: The phpMyAdmin installation process leaves the SQL install script with insecure permissions. A local attacker could exploit this vulnerability to obtain the initial phpMyAdmin password and from there obtain information about databases accessible by phpMyAdmin.
Alerts:
Gentoo 200504-30 2005-04-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds