Lucene search

K
ubuntucveUbuntu.comUB:CVE-2016-9852
HistoryDec 11, 2016 - 12:00 a.m.

CVE-2016-9852

2016-12-1100:00:00
ubuntu.com
ubuntu.com
11

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.003

Percentile

69.0%

An issue was discovered in phpMyAdmin. By calling some scripts that are
part of phpMyAdmin in an unexpected way, it is possible to trigger
phpMyAdmin to display a PHP error message which contains the full path of
the directory where phpMyAdmin is installed. During an execution timeout in
the export functionality, the errors containing the full path of the
directory of phpMyAdmin are written to the export file. All 4.6.x versions
(prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This
CVE is for the curl wrapper issue.

OSVersionArchitecturePackageVersionFilename
ubuntu16.04noarchphpmyadmin< anyUNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.003

Percentile

69.0%