Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000499

Опубликовано: 03 янв. 2018
Источник: debian
EPSS Средний

Описание

phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phpmyadminnot-affectedpackage

Примечания

  • https://www.phpmyadmin.net/security/PMASA-2017-9/

  • https://github.com/phpmyadmin/phpmyadmin/commit/edd929216ade9f7c150a262ba3db44db0fed0e1b (4.7-branch)

  • https://github.com/phpmyadmin/phpmyadmin/commit/72f109a99c82b14c07dcb19946ba9b76efc32a1b (4.8-branch)

EPSS

Процентиль: 93%
0.10452
Средний

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.

CVSS3: 8.8
nvd
больше 7 лет назад

phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.

CVSS3: 8.8
github
около 3 лет назад

phpMyAdmin CSRF Vulnerability

EPSS

Процентиль: 93%
0.10452
Средний