Description
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
Remediation
References
Related Vulnerabilities
Ruby on Rails Use of Externally-Controlled Format String Vulnerability (CVE-2013-4389)
MySQL CVE-2019-2481 Vulnerability (CVE-2019-2481)
PHP Improper Encoding or Escaping of Output Vulnerability (CVE-2024-5585)
MySQL Numeric Errors Vulnerability (CVE-2010-3835)
WordPress 3.7.x Cross-Domain Flash Injection Vulnerability (3.7 - 3.7.24)