An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/92494 | vdb entry third party advisory |
https://www.phpmyadmin.net/security/PMASA-2016-50 | patch vendor advisory |
https://security.gentoo.org/glsa/201701-32 | vendor advisory |
https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html | mailing list |