phpMyAdmin < 4.6.2 Information Disclosure (PMASA-2016-14)
Low Nessus Network Monitor Plugin ID 9358
SynopsisThe remote web server contains a PHP application that is affected by an information disclosure vulnerability.
DescriptionVersions of phpMyAdmin prior to 4.6.2 are unpatched for an information disclosure vulnerability which may leak sensitive SQL details. Such versions contain a flaw that is triggered as user's SQL queries are part of the URL, which may disclose them when accessing external links from within the web application. This may allow a context-dependent attacker to potentially gain knowledge of sensitive information.
SolutionUpgrade to phpMyAdmin 4.6.2 or later. Alternatively, ensure all phpMyAdmin links are redirected through the 'url.php' script.