Information disclosure in phpMyAdmin - CVE-2016-6627

 

Information disclosure in phpMyAdmin - CVE-2016-6627

Published: December 11, 2016 / Updated: August 4, 2020


Vulnerability identifier: #VU33624
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6627
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.


Affected software

phpMyAdmin
phpmyadmin (Alpine package)
Opensuse

How to mitigate CVE-2016-6627

Install update from vendor's website.

phpmyadmin (Alpine package) - update to 4.4.15.8-r0

External References

Related Security Bulletins