CVE-2016-9853

Source
https://cve.org/CVERecord?id=CVE-2016-9853
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9853.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-9853
Aliases
Downstream
Related
Published
2016-12-11T02:59:51.477Z
Modified
2026-04-10T03:55:29.831360Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the fopen wrapper issue.

References

Affected packages

Git / github.com/phpmyadmin/phpmyadmin

Affected ranges

Type
GIT
Repo
https://github.com/phpmyadmin/phpmyadmin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.1.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.6.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.7"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.8"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.9"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.10"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.11"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.12"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.13"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.13.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.14"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.14.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.15"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.15.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.15.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.15.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.15.4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.15.5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.15.6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.15.7"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.4.15.8"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.6.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.6.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.6.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.6.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.6.4"
        }
    ]
}

Affected versions

Other
RELEASE_2_2_0
RELEASE_2_2_1
RELEASE_2_2_2
RELEASE_2_2_3
RELEASE_2_2_4
RELEASE_2_2_5
RELEASE_2_2_6
RELEASE_2_2_7PL1
RELEASE_2_3_0
RELEASE_2_3_1
RELEASE_2_3_2
RELEASE_2_3_3PL1
RELEASE_2_4_0
RELEASE_2_5_0
RELEASE_2_5_1
RELEASE_2_5_2
RELEASE_2_5_4
RELEASE_2_5_5PL1
RELEASE_2_5_6
RELEASE_2_5_7PL1
RELEASE_2_6_1PL3
RELEASE_2_6_2PL1
RELEASE_2_6_3PL1
RELEASE_2_6_4PL4
RELEASE_2_7_0PL2
RELEASE_2_8_0_4
RELEASE_2_8_1
RELEASE_2_8_2_4
RELEASE_2_9_0
RELEASE_3_4_0RC2
RELEASE_3_5_0ALPHA1
RELEASE_4_0_0ALPHA2
RELEASE_4_0_0BETA3
RELEASE_4_0_0RC1
RELEASE_4_1_0ALPHA1
RELEASE_4_1_0BETA1
RELEASE_4_1_0BETA2
RELEASE_4_2_0ALPHA2
RELEASE_4_2_0BETA1
RELEASE_4_4_0
RELEASE_4_4_0ALPHA1
RELEASE_4_4_1
RELEASE_4_4_10
RELEASE_4_4_11
RELEASE_4_4_12
RELEASE_4_4_13
RELEASE_4_4_13_1
RELEASE_4_4_14
RELEASE_4_4_14_1
RELEASE_4_4_15
RELEASE_4_4_15_1
RELEASE_4_4_15_2
RELEASE_4_4_15_3
RELEASE_4_4_15_4
RELEASE_4_4_15_5
RELEASE_4_4_15_6
RELEASE_4_4_15_7
RELEASE_4_4_15_8
RELEASE_4_4_1_1
RELEASE_4_4_2
RELEASE_4_4_3
RELEASE_4_4_4
RELEASE_4_4_5
RELEASE_4_4_6
RELEASE_4_4_6_1
RELEASE_4_4_7
RELEASE_4_4_8
RELEASE_4_4_9
RELEASE_4_6_0
RELEASE_4_6_0ALPHA1
RELEASE_4_6_0RC2
RELEASE_4_6_1
RELEASE_4_6_2
RELEASE_4_6_3
RELEASE_4_6_4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9853.json"