phpMyAdmin < 4.6.2 Information Disclosure (PMASA-2016-14)

Low Nessus Network Monitor Plugin ID 9358

Synopsis

The remote web server contains a PHP application that is affected by an information disclosure vulnerability.

Description

Versions of phpMyAdmin prior to 4.6.2 are unpatched for an information disclosure vulnerability which may leak sensitive SQL details. Such versions contain a flaw that is triggered as user's SQL queries are part of the URL, which may disclose them when accessing external links from within the web application. This may allow a context-dependent attacker to potentially gain knowledge of sensitive information.

Solution

Upgrade to phpMyAdmin 4.6.2 or later. Alternatively, ensure all phpMyAdmin links are redirected through the 'url.php' script.

See Also

https://www.phpmyadmin.net/security

https://www.phpmyadmin.net/security/PMASA-2016-14

Plugin Details

Severity: Low

ID: 9358

Family: CGI

Published: 2016/06/17

Modified: 2016/06/17

Dependencies: 9102

Risk Information

Risk Factor: Low

CVSSv2

Base Score: 2.6

Temporal Score: 2.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

CVSSv3

Base Score: 3.6

Temporal Score: 3.4

Vector: CVSS3#AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS3#E:X/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:phpmyadmin:phpmyadmin

Patch Publication Date: 2016/02/25

Vulnerability Publication Date: 2016/02/25

Reference Information

CVE: CVE-2016-5097