CVE-2013-4998: phpMyAdmin

Medium severity, CVSS 5.0. EPSS: 1.8% chance of exploitation in the next 30 days.

phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files.

Affected products

  • phpMyAdmin phpMyAdmin: version 3.5.0.0 only; version 3.5.1.0 only; version 3.5.2.0 only; version 3.5.2.1 only; version 3.5.2.2 only; version 3.5.3.0 only; …

Published 2013-07-31. Last modified 2026-06-16.