CVE-2016-9853: Infoleak
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the fopen wrapper issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9853?
CVE-2016-9853 has a moderate severity rating due to its potential to expose sensitive directory information through PHP error messages.
How do I fix CVE-2016-9853?
To fix CVE-2016-9853, update phpMyAdmin to version 4.4.14 or later.
What does CVE-2016-9853 affect?
CVE-2016-9853 specifically affects phpMyAdmin versions 4.4.0 to 4.4.13.
What are the consequences of exploiting CVE-2016-9853?
Exploiting CVE-2016-9853 could allow an attacker to view the full path of the phpMyAdmin installation, aiding in further attacks.
How can I determine if I am using a vulnerable version for CVE-2016-9853?
You can determine if you are using a vulnerable version by checking your phpMyAdmin version against the affected versions listed for CVE-2016-9853.