DELTA 538349 0 25425 SVN-x,fw(vi[V~D~E4Xx^QN0=ӯqO 4PJEH$4VmO[- `{<3*x}^\tW]VEռ*n/u=<-;ɁYܮ&ݜ"C\(p;]S"iN=|ZNǔA Qt -=3ZY)yg}(G,\bK d= `ރGGKmGمPoYPSbcɿ}s/ꏣ5i DS!_Ӌ-{yh}Wn5vٽ!&Im3޸̟;0U7Vvi~չ8GrV8+kuxs 1&Yq}ۆfv}QZ@_R} Rx^Ao0Wzn-{XU!*!(=:cd׻p%=}omsDnjF?P8iպZ}ͩPq70P"E*$',I 6W;VJT:6uoEC䁤h Fa޸c,~$!OF8͘vjGṵsuOgU]{ҙ YH2qN6̮Mʹ%&pl{6Y|hK> Y~Zy}u@O=jx^RM0<7sm#Ip}hhJЅ.K+KFOv{x̛$ԡUa>Cܣ=ۦ}]uF̧X'E|],ٔyvF6X:Ճub]b/YQ#vPT^ću& *b/+ƌ!CY-˖gъM6*^ &%~䛼k/yY&yﻔ$4;Y.)_F{kb:rp ŸΓ )ݓ[<3dSG>ѪI CK뢁7MQ-YcV,)M clp3 8;8 89Ac{&{EZ [,f&XC WE~tWā VivQ-隗88ΓXhq ^_71ʊlsޠ KZhQ6ߔ$40-lM3A_1 X8ؑi?X)' .7c;{>YSR5fZ) ^DT{}./)-CIfnD!,]ͨd4 WF +p;=@S[-zU*6C|J+BL,؛ ٱݯީ}:0Q?^zdOt!e9{8gS'!-?(.|ԓuJ Q'MzqKr |[Nޒ][Rl5u{ĀZhAp.cԼAKmnTKAeN[ ec埠{V*Q4 Mx^uOo0)F@hWaDO q]9]6ݱ(o{㺴uvX,.!@7_for6rwG8H[YH@[0ޤk;mQԥr^Cp @i+n[ م{ I(MlSo(c*(4…]Ir\Q@U-~9b8[NTI2MQHl*rIG2[h.Z"$$ _sX!.oArKj\ ).<ԲL9#,բ=n\=Ѵ0icOR =|(FN`Kӓ6<%ZRkb`7}ခKqGS;"-p'%+8Dc/m48rP}1%v䶠ȹ ,|u M1!P XSS!:0-lX7pjB޳kcQ9Ym<@I jcZV R)B X7X0qKa՞=V`,  /`;\<=|̣ſ$w#brda8d{@qxv Ex^Rn0<_9zP,` b(VIFZ)ll%).%$% 93KY`>LpgUb[-9/4ZE3ZpK5:h<5&+D]VC]3 G;WH6 h;'@GVfK gI.)P{'܉ W84\*A<] %%"~ȰaئU*"o]2-֛*y=C{5-i msӴ.e*J~xmF@cYt@=Ǒ4h#3pcM&{;2}:yɒxJNF1[.0/sA t tx^Sn1=Wrm*!JU*i"+ړUنglY7yy WuUc|EGR~D}az ;S9E"PO/>^?gӋ٧K'-<Y /:$nPPFӠB@C.ۀKn PǑ1a 0~vǍ@&8Uig 1@+ 2G+ 0&PZu5܆Ka H{-"zv qeF"_"F%:mQ%$#j!BWIETܖ,cj&kҲ͗Ed_3E]>?^"DقD5Fۗ IH?Q-&m91:!qCFQ;94:H#*z:쀶 yyx\CUUr|ϣu|=!_87{a=[xL &ԁF\L@E,tk,,Ğ }BE & PCWfqՔ fӊy(FK8.k[&\co\2 bɊ]r{8ekz\~o,~ Zt tx^USMoS1<ïXT$ !@pRA}<䏆ǯgNBgwvfvdS-d1~EdPbr{ؓɓp^h`Z} %9gwoE)KzC\\`fKcJGI B@ +t@?= p'qڱ2>$fuKə tyȡx$P$@8vYjuHR86,mvwڧ݄Jb#gH*b53h&Zg k1$`žPqUYEa^CݓVlE?2Qa}`5k9ֆX 8,$f]Naxzlocc>a'rTyj+ySZY"6 Ne3d]iHŅ%B>žwB&dN 7ԃ8'S=J'NQnZK'w͜-"pܲftqB= C] essrK 2FߞKHgoTE!eTˀ 5,? t tx^KO0+Bi!BAԵ =N[U\>N,z ^u3)w+m'L*B C8z$~FM2yِbszm .t%EuwsS X'`.{_>ꤵ^fN:+*'|"hUϜpK[z7 m'$[N@3&hvTqmLQe4GkopXUL!Zk3\Ox';IXOrq(^v8ϲ1@ˍ"!zK;y(Mq?e$ s"k"`tz&뙢"&&s{=C#z==ηLD~_? x^Sn@=_1V"Ic+u-Re0,tXܯ@ 2#\؅޼y^;oO߯xq{,$Zu'Xb|F#1kjmhO9^ӾKs5DxUk Yr@Jn{Ȉ!dPfdxsR7pShZ/?±Vp*1L[&,BcS§^!O}>3kepM lgm&'7iw,w-u;qVd 7B-qδ׋k+Oq|NTQZ'7iZh߹V A^d.JO6̢VI20*bl8 |.&%NIg!prnF,zDQucTBq!J;ˀ&%kU@MB~!w~nu0\Gx^Rˊ0<|EF-?4YC=. Km[D~ KGS UU-?›=,Ak~fT6h |'dt HjsR}o)9SToV,x R* pĆ{gՊDVgUj)^cuSA|i %#Y!Ѽlkc}`5CtQQe@Nd(L^pY٨ZnLԭv"5mQy|g z-c1 %i%'6r\jå3H#{= :`p%{'p[G|2ZѠN@JN?PvT8x^SM0<7S+-O"6RvUm٘Xql6iL>6 a+6 Z;c[[>2b Ǩ[1P(Kmq.&ex'lezr^ *%j 8PUo?A|Jb{Sa ] ¿[g< -x&!%L>,[%:v*Xxx^0Sr^c l#/jzz0j߾6ͥ*\fj  &Jv3HB`λwaBE&(5F0J\bf++f_%ނ{U}g߲#A|fhѡ/`m SO;TYU`ŊLQCeY )VX,/,y\Dz~ Lu̓n ov!tI"h1cѫNȋfI|>މ1dOOM˧eZ6?7ZC!I;} yj"5% ȍ4ߡ>#^M3E{%K>8؁VV_Jt7Pqokž8- hN0UA"ʨ j^t?=%7M>p 'x^Rj0}nwY2@ {Z J)tWi%WW'{Zs=,Ǘ"ұW Vכzl׋=0fxl?yuDON(|N"#5'@AzE?r4B@@HD zP" HdxȈ a LԀ?m>kzr|94?\{zϹ*CP}LdV7;R bd76Cgb'1~v:3%qِPT,߶;al . wgS(|1|zQU\\ ]q{($X`7>k]-/p|W,Jyl0L9s>9]$0׊9fF([`8NJ?s? 7x^mSN@=qi+vB"cz q3uw7=6jԃe{y)&<>Ab9*Yg*<)rJ{T@lǪ0[lMCE.y:KgyO:i]q7A_qʚl<-Amlvj~#?ߑyŎŁ.O!t~eQسOk2279,Y qfU%d1'v#MgbDv5{,5M*ʳ5؎:U^õ5_i1B!Pۅ862Ct^ssR`4v͝ _2=;kZ2ztTbbE#=;s\ {n2a~? BĊa1 J^ud%!OXN7'gO7e]4(]y+OEZÎJT®" b @!j4+k._[o) \`6y\koYaMcBy0'EzKg/@VՐl)D^"AEhT4]vL9Y'iN!Y=n(zh;Z=CԒ'+)ROo:H7?ǾeW‘ϙIҭ&uERLO⹗zcTN Z=,*[dyިt5M![TaA\봬 Y` h@Z- &{h iۖdѡܥ0Lw4ƙhӲ0^-?V_hO߾|js_k2%|$v`mjJ0u[TJ"jkx^n0E+S\ !uBhQBTwHG^uzTz]缬p)Snpb ͸ʴ6g \m `V&sah*IcCQIK0ʊ?]-Eu׏-Q@V&O#lOEI<%X,BXUV ~-e؟ ^ 0{#%>fD~j".8/">

By calling a particular script that is part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed.

We consider this vulnerability8/ CVE-2016-2044694927f-c60b-11e5-bf36-6805ca0b3d42"> phpmyadmin -- XSS vulnerability in normalization page%L$gw@YBCxZGn%x^RM0+IN(yq~b,M#s!59vE2vbL'O(II ӡ,xZ7H#$ٵ)z (tvFbI&?4=-95mi8^_e/KMSr.x ͳMSR?'Fh*LP!m]HZTr(E''&pv PyCrh$x^ePˎ0]ӯ &i"  9Mbt\' 1>>/ߺy6ք~Sc5vƚ2N_;0"/ɺ'AQˆRCt$+9Kՠ '8[:r%:S$A0ЖLAWxohG^=%?6C'^ж&ɤMpZ}+ w+ݖ ^ "; dĐ/i& f?oX#?Qx  Ex:eyE7Ռlm:t܁OU)bw-@,#!`hb / 8.7@H<H<Hhttps://www.mozilla.org/security/advisories/mfsa2015-111112113114/ 2015-09-22 2015-09-22 ffmpeglibav90 gstreamer-ffmpeg