---
cve: "CVE-2015-8669"
severity: "LOW"
cvss: 3.1
epss: "2.2%"
vendor: "n/a"
kev: false
exploited: false
published: "2015-12-26 22:59:01"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-03T02:59:51+02:00"
---

# CVE-2015-8669

> 3.1 LOW · 🧪 PoC

## Beschreibung

libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.

## Referenzen

- <http://lists.opensuse.org/opensuse-updates/2016-01/msg00014.html>
- <https://www.phpmyadmin.net/security/PMASA-2015-6/>
- <http://www.securitytracker.com/id/1034806>
- <https://github.com/phpmyadmin/phpmyadmin/commit/c4d649325b25139d7c097e56e2e46cc7187fae45>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2015-8669) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
