CVE-2016-6627: Infoleak
An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6627?
CVE-2016-6627 has a medium severity rating due to its ability to leak information about the phpMyAdmin host location.
How do I fix CVE-2016-6627?
To fix CVE-2016-6627, upgrade phpMyAdmin to version 4.6.4 or later, or 4.4.15.8, or 4.0.10.17 or later.
Which versions of phpMyAdmin are affected by CVE-2016-6627?
All versions of phpMyAdmin 4.6.x prior to 4.6.4, 4.4.x prior to 4.4.15.8, and 4.0.x prior to 4.0.10.17 are affected.
What potential impact does CVE-2016-6627 have on phpMyAdmin?
CVE-2016-6627 may allow an attacker to determine the host location of the phpMyAdmin installation.
Is there a workaround for CVE-2016-6627 if I cannot update phpMyAdmin?
If you cannot update phpMyAdmin, limiting access to the url.php file through server configurations may help mitigate the risk.