Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-6625

Опубликовано: 11 дек. 2016
Источник: debian
EPSS Низкий

Описание

An issue was discovered in phpMyAdmin. An attacker can determine whether a user is logged in to phpMyAdmin. The user's session, username, and password are not compromised by this vulnerability. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phpmyadminfixed4:4.6.4+dfsg1-1package

Примечания

  • https://www.phpmyadmin.net/security/PMASA-2016-48/

  • The solution is to remove a configuration option. This option

  • is by default disabled so a default installation is not

  • vulnerable. It should be fairly obvious that enabling phpinfo

  • printing can show more information than what should be used in

  • a production environment. This is the motivation that it is not

  • solved for wheezy.

EPSS

Процентиль: 45%
0.00221
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 8 лет назад

An issue was discovered in phpMyAdmin. An attacker can determine whether a user is logged in to phpMyAdmin. The user's session, username, and password are not compromised by this vulnerability. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 4.3
nvd
больше 8 лет назад

An issue was discovered in phpMyAdmin. An attacker can determine whether a user is logged in to phpMyAdmin. The user's session, username, and password are not compromised by this vulnerability. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 4.3
github
около 3 лет назад

phpMyAdmin allows to detect if user is logged in

suse-cvrf
почти 9 лет назад

Security update for phpMyAdmin

EPSS

Процентиль: 45%
0.00221
Низкий