An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.
References
Link | Resource |
---|---|
https://www.phpmyadmin.net/security/PMASA-2016-57 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/94519 | Third Party Advisory VDB Entry |
https://security.gentoo.org/glsa/201701-32 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2016-12-10 18:59
Updated : 2017-06-30 18:29
NVD link : CVE-2016-4412
Mitre link : CVE-2016-4412
JSON object : View
CWE
CWE-254
7PK - Security Features
Products Affected
phpmyadmin
- phpmyadmin