Information Exposure Through an Error Message Affecting phpmyadmin/phpmyadmin package, versions >=4.0.0, <4.0.10.17 >=4.4.0, <4.4.15.8 >=4.6.0, <4.6.4
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-PHPMYADMINPHPMYADMIN-6673890
- published 25 Apr 2024
- disclosed 17 May 2022
- credit Emanuel Bronshtein
Introduced: 17 May 2022
CVE-2016-6613 Open this link in a new tabHow to fix?
Upgrade phpmyadmin/phpmyadmin
to version 4.0.10.17, 4.4.15.8, 4.6.4 or higher.
Overview
phpmyadmin/phpmyadmin is a web interface for MySQL and MariaDB.
Affected versions of this package are vulnerable to Information Exposure Through an Error Message due to the improper handling of symbolic links in the UploadDir
feature. An attacker can gain access to files that phpMyAdmin is allowed to read but the attacker is not, by crafting a symbolic link to such a file. This exposure occurs when the symbolic link points to a restricted file, effectively bypassing the intended file access restrictions.