CVE-2016-5730

MEDIUM

phpMyAdmin <4.0.10.16, <4.4.15.7, <4.6.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to obtain sensitive information via vectors involving (1) an array value to FormDisplay.php, (2) incorrect data to validate.php, (3) unexpected data to Validator.php, (4) a missing config directory during setup, or (5) an incorrect OpenID identifier data type, which reveals the full path in an error message.

Scores

CVSS v3 5.3
EPSS 0.0132
EPSS Percentile 80.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (47)
opensuse/leap 42.1
opensuse/opensuse 13.1
opensuse/opensuse 13.2
phpmyadmin/phpmyadmin 4.0.0
phpmyadmin/phpmyadmin 4.0.1
phpmyadmin/phpmyadmin 4.0.2
phpmyadmin/phpmyadmin 4.0.3
phpmyadmin/phpmyadmin 4.0.4
phpmyadmin/phpmyadmin 4.0.4.1
phpmyadmin/phpmyadmin 4.0.4.2
... and 37 more
Published Jul 03, 2016
Tracked Since Feb 18, 2026