Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

phpMyAdmin < 4.6.2 Information Disclosure (PMASA-2016-14)

Low

Synopsis

The remote web server contains a PHP application that is affected by an information disclosure vulnerability.

Description

Versions of phpMyAdmin prior to 4.6.2 are unpatched for an information disclosure vulnerability which may leak sensitive SQL details. Such versions contain a flaw that is triggered as user's SQL queries are part of the URL, which may disclose them when accessing external links from within the web application. This may allow a context-dependent attacker to potentially gain knowledge of sensitive information.

Solution

Upgrade to phpMyAdmin 4.6.2 or later. Alternatively, ensure all phpMyAdmin links are redirected through the 'url.php' script.