Description
phpMyAdmin 2.9.1.1 allows remote attackers to obtain sensitive information via a direct request for themes/darkblue_orange/layout.inc.php, which reveals the path in an error message.
Remediation
References
Related Vulnerabilities
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2026-35300)
WordPress Plugin Advanced Advertising System PHP Object Injection (1.3.1)
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-21673)
PHP Improper Input Validation Vulnerability (CVE-2012-0788)
WordPress Plugin Brizy-Page Builder Unspecified Vulnerability (2.4.45)