Описание
phpMyAdmin Authentication Bypass
An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp']
configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Пакеты
phpmyadmin/phpmyadmin
>= 4.6, < 4.6.4
4.6.4
phpmyadmin/phpmyadmin
>= 4.4, < 4.4.15.8
4.4.15.8
phpmyadmin/phpmyadmin
>= 4.0, < 4.0.10.17
4.0.10.17
Связанные уязвимости
An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
An issue was discovered in phpMyAdmin involving the $cfg['ArbitrarySer ...