Information disclosure in phpMyAdmin - CVE-2016-9848

 

Information disclosure in phpMyAdmin - CVE-2016-9848

Published: December 11, 2016 / Updated: August 4, 2020


Vulnerability identifier: #VU33347
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9848
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.


Affected software

phpMyAdmin
phpmyadmin (Alpine package)

How to mitigate CVE-2016-9848

Install update from vendor's website.

phpmyadmin (Alpine package) - update to 4.4.15.9-r0

External References

Related Security Bulletins