Information disclosure in phpMyAdmin - CVE-2016-6610
Published: December 11, 2016 / Updated: August 4, 2020
phpMyAdmin
Detailed vulnerability description
The vulnerability allows a remote authenticated user to gain access to sensitive information.
A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.