CVE-2016-6610
4.3
MEDIUM
CVSS 3.1
EPSS 0.32%
Description
A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
How to fix CVE-2016-6610
To remediate CVE-2016-6610, upgrade the affected package to a fixed version below.
- Alpine/phpmyadmin—upgrade to 4.4.15.8-r0 or later
- —upgrade to 4:4.6.4+dfsg1-1 or later
Is CVE-2016-6610 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 4.4.15.8-r0
- from 0, < 4:4.6.4+dfsg1-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |