CVE-2016-5730

medium
Published 2016-07-03 · Modified 2024-04-24
CVSS v3
5.3
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2
5.0
VIR risk
5.3

Description

phpMyAdmin full path disclosure vulnerability

Predictions

Exploit likelihood
63%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-5730

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.phpmyadmin.net/security/PMASA-2016-23/

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/cd229d718e8cb4bc8ba32446beaa82d27727b6f0

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/b0180f18c828706af3a6800f0fb01a536d3ef8c7

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/96e0aa35653ec0c66084a7e9343465e16c1f769b

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/331c560fbfa0e7d2dce674b5e88e983c5f2a451d

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/27664605b945b13e1d2b71adea822ace2099cc96

OS impact

OSVersionStatusFixed in
suse suse42.1affected
suse suse13.1affected
suse suse13.2affected
debian debianbookwormfixed4:4.6.3-1
debian debianbullseyefixed4:4.6.3-1
debian debiansidfixed4:4.6.3-1
debian debiantrixiefixed4:4.6.3-1

Package impact

EcosystemPackageVulnerableFixed
php Packagistphpmyadmin/phpmyadmin>=4.0,<4.0.10.164.0.10.16
php Packagistphpmyadmin/phpmyadmin>=4.4,<4.4.15.74.4.15.7
php Packagistphpmyadmin/phpmyadmin>=4.6,<4.6.34.6.3

Application impact

VendorProductVersionsFixed
phpmyadminphpmyadmin4.0.0
phpmyadminphpmyadmin4.0.1
phpmyadminphpmyadmin4.0.2
phpmyadminphpmyadmin4.0.3
phpmyadminphpmyadmin4.0.4
phpmyadminphpmyadmin4.0.4.1
phpmyadminphpmyadmin4.0.4.2
phpmyadminphpmyadmin4.0.5
phpmyadminphpmyadmin4.0.6
phpmyadminphpmyadmin4.0.7
phpmyadminphpmyadmin4.0.8
phpmyadminphpmyadmin4.0.9
phpmyadminphpmyadmin4.0.10
phpmyadminphpmyadmin4.0.10.1
phpmyadminphpmyadmin4.0.10.2
phpmyadminphpmyadmin4.0.10.3
phpmyadminphpmyadmin4.0.10.4
phpmyadminphpmyadmin4.0.10.5
phpmyadminphpmyadmin4.0.10.6
phpmyadminphpmyadmin4.0.10.7
phpmyadminphpmyadmin4.0.10.8
phpmyadminphpmyadmin4.0.10.9
phpmyadminphpmyadmin4.0.10.10
phpmyadminphpmyadmin4.0.10.11
phpmyadminphpmyadmin4.0.10.12
phpmyadminphpmyadmin4.0.10.13
phpmyadminphpmyadmin4.0.10.14
phpmyadminphpmyadmin4.0.10.15
phpmyadminphpmyadmin4.6.0
phpmyadminphpmyadmin4.6.1
phpmyadminphpmyadmin4.6.2
phpmyadminphpmyadmin4.4.0
phpmyadminphpmyadmin4.4.1
phpmyadminphpmyadmin4.4.1.1
phpmyadminphpmyadmin4.4.2
phpmyadminphpmyadmin4.4.3
phpmyadminphpmyadmin4.4.4
phpmyadminphpmyadmin4.4.5
phpmyadminphpmyadmin4.4.6
phpmyadminphpmyadmin4.4.6.1
phpmyadminphpmyadmin4.4.7
phpmyadminphpmyadmin4.4.8
phpmyadminphpmyadmin4.4.9
phpmyadminphpmyadmin4.4.10
phpmyadminphpmyadmin4.4.11
phpmyadminphpmyadmin4.4.12
phpmyadminphpmyadmin4.4.13
phpmyadminphpmyadmin4.4.13.1
phpmyadminphpmyadmin4.4.14.1
phpmyadminphpmyadmin4.4.15
phpmyadminphpmyadmin4.4.15.1
phpmyadminphpmyadmin4.4.15.2
phpmyadminphpmyadmin4.4.15.3
phpmyadminphpmyadmin4.4.15.4
phpmyadminphpmyadmin4.4.15.5
phpmyadminphpmyadmin4.4.15.6

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.