CVE-2016-2038Sensitive Information Exposure in Phpmyadmin

Severity
5.3MEDIUMNVD
EPSS
1.2%
top 21.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20
Latest updateMay 14

Description

phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

debiandebian/phpmyadmin< phpmyadmin 4:4.5.4-1 (bookworm)
Debianphpmyadmin/phpmyadmin< 4:4.5.4-1+3
NVDphpmyadmin/phpmyadmin43 versions+42
NVDopensuse/leap42.1
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Fedora 22, 23

Patches

🔴Vulnerability Details

2
GHSA
GHSA-75vh-37rf-cpgj: phpMyAdmin 42022-05-14
OSV
CVE-2016-2038: phpMyAdmin 42016-02-20

📋Vendor Advisories

1
Debian
CVE-2016-2038: phpmyadmin - phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4...2016

💬Community

3
Bugzilla
CVE-2016-2038 CVE-2016-2039 CVE-2016-2040 CVE-2016-1927 CVE-2016-2041 CVE-2016-2043 CVE-2016-2044 CVE-2016-2045 phpmyadmin: various flaws [fedora-all]2016-01-28
Bugzilla
CVE-2016-2038 CVE-2016-2039 CVE-2016-2040 CVE-2016-1927 CVE-2016-2041 CVE-2016-2043 CVE-2016-2044 CVE-2016-2045 phpmyadmin: various flaws [epel-all]2016-01-28
Bugzilla
CVE-2016-2038 phpMyAdmin: Multiple full path disclosure vulnerabilities (PMASA-2016-1)2016-01-28