Information disclosure in phpMyAdmin - CVE-2016-6627
Published: December 11, 2016 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected software
phpmyadmin (Alpine package)
Opensuse