CVE-2008-1924
Publication date 23 April 2008
Last updated 24 July 2024
Ubuntu priority
Description
Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variable.