CVE-2016-2044: Fedoraproject Fedora

Medium severity, CVSS 5.3. EPSS: 2% chance of exploitation in the next 30 days.

libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.

Affected products

  • Fedoraproject Fedora: version 22 only; version 23 only
  • phpMyAdmin phpMyAdmin: version 4.5.0 only; version 4.5.0.1 only; version 4.5.0.2 only; version 4.5.1 only; version 4.5.2 only; version 4.5.3 only

Published 2016-02-20. Last modified 2026-06-17.