CVE-2016-2042
published 2016-02-20CVE-2016-2042: phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1)…
PriorityP419medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
2.38%
82.0th percentile
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:4.5.4-1 (bookworm) | phpmyadmin 4:4.5.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
phpMyAdmin: Multiple full path disclosure vulnerabilities (PMASA-2016-6)
vendor_redhat·2016-01-28·CVSS 5.3
CVE-2016-2042 [MEDIUM] CWE-200 phpMyAdmin: Multiple full path disclosure vulnerabilities (PMASA-2016-6)
phpMyAdmin: Multiple full path disclosure vulnerabilities (PMASA-2016-6)
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
Debian
CVE-2016-2042: phpmyadmin - phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers ...
vendor_debian·2016·CVSS 5.3
CVE-2016-2042 [MEDIUM] CVE-2016-2042: phpmyadmin - phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers ...
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
Scope: local
bookworm: resolved (fixed in 4:4.5.4-1)
bullseye: resolved (fixed in 4:4.5.4-1)
forky: resolved (fixed in 4:4.5.4-1)
sid: resolved (fixed in 4:4.5.4-1)
trixie: resolved (fixed in 4:4.5.4-1)
GHSA
GHSA-g564-g9wm-3q4m: phpMyAdmin 4
ghsa_unreviewed·2022-05-14
CVE-2016-2042 [MEDIUM] CWE-200 GHSA-g564-g9wm-3q4m: phpMyAdmin 4
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
OSV
CVE-2016-2042: phpMyAdmin 4
osv·2016-02-20·CVSS 5.3
CVE-2016-2042 [MEDIUM] CVE-2016-2042: phpMyAdmin 4
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176483.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176739.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00049.htmlhttp://www.phpmyadmin.net/home_page/security/PMASA-2016-6.phphttps://github.com/phpmyadmin/phpmyadmin/commit/5a3de108f26e4b0dddadddbe8ccdb1dd5526771fhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176483.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176739.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00049.htmlhttp://www.phpmyadmin.net/home_page/security/PMASA-2016-6.phphttps://github.com/phpmyadmin/phpmyadmin/commit/5a3de108f26e4b0dddadddbe8ccdb1dd5526771f
2016-02-20
Published