CVE-2015-8669: Infoleak
libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8669?
CVE-2015-8669 has a medium severity level as it allows remote attackers to obtain sensitive information.
How do I fix CVE-2015-8669?
To fix CVE-2015-8669, you should upgrade phpMyAdmin to version 4.0.10.12 or later, 4.4.15.2 or later, or 4.5.3.1 or later.
What versions of phpMyAdmin are affected by CVE-2015-8669?
CVE-2015-8669 affects phpMyAdmin versions 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1.
What kind of information can be leaked due to CVE-2015-8669?
CVE-2015-8669 allows attackers to reveal the full path in an error message, potentially leaking sensitive information about the server.
Is CVE-2015-8669 a local or remote vulnerability?
CVE-2015-8669 is a remote vulnerability, allowing attackers to exploit it without direct access to the target system.