phpMyAdmin < 4.6.2 Information Disclosure (PMASA-2016-14)

low Nessus Network Monitor Plugin ID 9358

Synopsis

The remote web server contains a PHP application that is affected by an information disclosure vulnerability.

Description

Versions of phpMyAdmin prior to 4.6.2 are unpatched for an information disclosure vulnerability which may leak sensitive SQL details. Such versions contain a flaw that is triggered as user's SQL queries are part of the URL, which may disclose them when accessing external links from within the web application. This may allow a context-dependent attacker to potentially gain knowledge of sensitive information.

Solution

Upgrade to phpMyAdmin 4.6.2 or later. Alternatively, ensure all phpMyAdmin links are redirected through the 'url.php' script.

See Also

https://www.phpmyadmin.net/security

https://www.phpmyadmin.net/security/PMASA-2016-14

Plugin Details

Severity: Low

ID: 9358

Family: CGI

Published: 6/17/2016

Updated: 3/6/2019

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 2.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N

CVSS v3

Risk Factor: Low

Base Score: 3.7

Temporal Score: 3.6

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:X/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:phpmyadmin:phpmyadmin

Patch Publication Date: 2/25/2016

Vulnerability Publication Date: 2/25/2016

Reference Information

CVE: CVE-2016-5097