Bug 1182095 (CVE-2021-26939) - VUL-0: CVE-2021-26939: phpMyAdmin: attacker can dump phpMyAdmin SQL content
Summary: VUL-0: CVE-2021-26939: phpMyAdmin: attacker can dump phpMyAdmin SQL content
Status: RESOLVED INVALID
Alias: CVE-2021-26939
Product: openSUSE Distribution
Classification: openSUSE
Component: Basesystem (show other bugs)
Version: Leap 15.2
Hardware: Other Other
: P3 - Medium : Minor (vote)
Target Milestone: ---
Assignee: Christian Wittmer
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/277683/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-02-11 07:31 UTC by Alexander Bergmann
Modified: 2023-02-02 10:56 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2021-02-11 07:31:41 UTC
CVE-2021-26939

An information disclosure issue exists in henriquedornas 5.2.17 because an
attacker can dump phpMyAdmin SQL content.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-26939
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26939
https://github.com/0xrayan/CVE-/discussions/4
Comment 1 Andreas Stieger 2021-02-11 09:35:56 UTC
This vulnerability describes an SQL dump left in a publicly accessible web path of a web consultancy. This it not a software product, just an operational error. Not a problem with phpMyAdmin. The CVE itself should be disputed.
Comment 2 Andreas Stieger 2021-02-12 19:47:20 UTC
CVE disputed, not in phpMyAdmin
Comment 3 Marcus Meissner 2023-02-02 10:56:57 UTC
was done