S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2008-5587 Scanner

Detects 'Directory Traversal' vulnerability in phpPgAdmin affects v. 4.2.1 and earlier.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2008-5587
4.3
CVSS

Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the _language parameter to index.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

PhpPgAdmin is an open-source web-based administration tool for managing PostgreSQL databases. It provides a user-friendly interface for database administrators to manage and control their databases with ease. The tool is written in PHP and is widely used by developers and database administrators alike.

CVE-2008-5587 is a directory traversal vulnerability found in the libraries/lib.inc.php file of phpPgAdmin 4.2.1 and earlier versions. The vulnerability is triggered when the register_globals feature is enabled, allowing remote attackers to gain unauthorized access to sensitive files by manipulating the _language parameter to index.php.

Exploiting this vulnerability can lead to unauthorized disclosure of sensitive data, which can be devastating for organizations that rely on this tool to manage their databases. Attackers can use this vulnerability to gather sensitive data, such as passwords, configuration files, and other critical information, which can be used to compromise the system.

To protect against this vulnerability, it is essential to follow some simple steps, such as disabling the register_globals feature, applying security patches and updates to the software, and implementing access control and authentication mechanisms to limit unauthorized access.

Securityforall.com provides a detailed analysis of vulnerabilities in digital assets, including web applications, databases, and network infrastructures. The platform offers a range of pro features that allow users to quickly and easily identify vulnerabilities in their digital assets, including vulnerability scanning, penetration testing, and asset management. With securityforall.com, organizations can be proactive in managing their security risks, ensuring that they are always one step ahead of potential threats.

 

REFERENCES

Solution Advice

Precautions that can be taken include:

  • Disable the register_globals feature
  • Upgrade to the latest version of phpPgAdmin
  • Implement access control and authentication mechanisms
  • Use web application firewalls to block unauthorized requests
  • Ensure that the system is up to date with all security patches and updates

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2008-5587 scanner - Directory Traversal vulnerability in phpPgAdmin | S4E