Information disclosure in phpMyAdmin - CVE-2016-6612
Published: December 11, 2016 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a remote authenticated user to gain access to sensitive information.
An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected software
phpmyadmin (Alpine package)
Opensuse