Synopsis
The remote web server contains a PHP application that is affected by an information disclosure vulnerability.
Description
Versions of phpMyAdmin 4.0.x prior to 4.0.10.9, 4.2.x prior to 4.2.13.2, or 4.3.x prior to 4.3.11.1 are unpatched for an information disclosure vulnerability due to the length of compressed HTTPS responses not being hidden. This allows a remote attacker, using a series of crafted requests, to obtain the CSRF token via a BREACH attack.
Solution
Upgrade to phpMyAdmin 4.0.10.9 / 4.2.13.2 / 4.3.11.1 or later, or apply the patches referenced in the vendor advisory.