PhpMyAdmin full path leakage Vulnerability (CVE-2016-2044)
PhpMyAdmin full path leakage Vulnerability (CVE-2016-2044)
Release date:
Updated on:
Affected Systems:
PhpMyAdmin 4.5.4> 4.5.x
Description:
CVE (CAN) ID: CVE-2016-2044
Phpmyadmin is an online management tool for MySQL databases.
In phpMyAdmin 4.5.4 or earlier versions, libraries/SQL-parser/autoload. php In the SQL parser has a security vulnerability. Remote attackers can obtain sensitive information by constructing requests.
<* Source: Emanuel Bronshtein
*>
Suggestion:
Vendor patch:
PhpMyAdmin
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.phpmyadmin.net/home_page/security/PMASA-2016-6.php
Https://github.com/phpmyadmin/phpmyadmin/commit/447c88f4884fe30a25d38c331c31d820a19f8c93
This article permanently updates the link address: