Symlink Vulnerability in phpMyAdmin Exposes Restricted Files

Symlink Vulnerability in phpMyAdmin Exposes Restricted Files

CVE-2016-6613 · LOW Severity

AV:N/AC:H/AU:S/C:P/I:N/A:N

An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

Learn more about our User Device Pen Test.