Description
Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable).
Remediation
References
Related Vulnerabilities
WordPress CVE-2016-5832 Vulnerability (CVE-2016-5832)
PHP Other Vulnerability (CVE-2005-3392)
SharePoint Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-5059)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-5876)
MediaWiki Improper Access Control Vulnerability (CVE-2015-8001)