CVE-2016-5730
MEDIUMphpMyAdmin <4.0.10.16, <4.4.15.7, <4.6.3 - Info Disclosure
Title source: llmDescription
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to obtain sensitive information via vectors involving (1) an array value to FormDisplay.php, (2) incorrect data to validate.php, (3) unexpected data to Validator.php, (4) a missing config directory during setup, or (5) an incorrect OpenID identifier data type, which reveals the full path in an error message.
References (10)
Core 10
Core References
Patch x_refsource_confirm
https://github.com/phpmyadmin/phpmyadmin/commit/96e0aa35653ec0c66084a7e9343465e16c1f769b
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2016-06/msg00114.html
Patch x_refsource_confirm
https://github.com/phpmyadmin/phpmyadmin/commit/cd229d718e8cb4bc8ba32446beaa82d27727b6f0
Patch, Vendor Advisory x_refsource_confirm
https://www.phpmyadmin.net/security/PMASA-2016-23/
Patch x_refsource_confirm
https://github.com/phpmyadmin/phpmyadmin/commit/331c560fbfa0e7d2dce674b5e88e983c5f2a451d
Patch x_refsource_confirm
https://github.com/phpmyadmin/phpmyadmin/commit/b0180f18c828706af3a6800f0fb01a536d3ef8c7
Patch x_refsource_confirm
https://github.com/phpmyadmin/phpmyadmin/commit/27664605b945b13e1d2b71adea822ace2099cc96
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201701-32
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/91379
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2016-06/msg00113.html
Scores
CVSS v3
5.3
EPSS
0.0132
EPSS Percentile
80.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (47)
opensuse/leap
42.1
opensuse/opensuse
13.1
opensuse/opensuse
13.2
phpmyadmin/phpmyadmin
4.0.0
phpmyadmin/phpmyadmin
4.0.1
phpmyadmin/phpmyadmin
4.0.2
phpmyadmin/phpmyadmin
4.0.3
phpmyadmin/phpmyadmin
4.0.4
phpmyadmin/phpmyadmin
4.0.4.1
phpmyadmin/phpmyadmin
4.0.4.2
... and 37 more
Published
Jul 03, 2016
Tracked Since
Feb 18, 2026