CVE-2016-9848: Infoleak
An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9848?
CVE-2016-9848 has been classified as a medium severity vulnerability.
How do I fix CVE-2016-9848?
To fix CVE-2016-9848, upgrade to phpMyAdmin version 4.6.5 or later, or 4.4.15.9 or later, or 4.0.10.18 or later.
Which phpMyAdmin versions are affected by CVE-2016-9848?
phpMyAdmin versions prior to 4.6.5 for 4.6.x series, 4.4.15.9 for 4.4.x series, and 4.0.10.18 for 4.0.x series are affected by CVE-2016-9848.
What type of information does CVE-2016-9848 leak?
CVE-2016-9848 can leak sensitive information by exposing values of HttpOnly cookies through phpinfo.
Is there a workaround for CVE-2016-9848 if I cannot upgrade?
There are no specific workarounds for CVE-2016-9848; upgrading to a patched version is the recommended solution.