Описание
phpMyAdmin allows remote attackers to spoof content via the url parameter
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2015-7873
- https://github.com/phpmyadmin/phpmyadmin/commit/2b31866fe0b30b867aaf5b5fedb11adb354e037f
- https://github.com/phpmyadmin/phpmyadmin/commit/cd097656758f981f80fb9029c7d6b4294582b706
- https://web.archive.org/web/20161014120907/http://www.securitytracker.com/id/1034013
- https://web.archive.org/web/20200228052850/http://www.securityfocus.com/bid/77299
- https://www.phpmyadmin.net/security/PMASA-2015-5
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171311.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171326.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169987.html
- http://www.debian.org/security/2015/dsa-3382
Пакеты
Наименование
phpmyadmin/phpmyadmin
composer
Затронутые версииВерсия исправления
>= 4.4.0, < 4.4.15.1
4.4.15.1
Наименование
phpmyadmin/phpmyadmin
composer
Затронутые версииВерсия исправления
>= 4.5.0, < 4.5.1
4.5.1
Связанные уязвимости
ubuntu
почти 10 лет назад
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
nvd
почти 10 лет назад
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
debian
почти 10 лет назад
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 ...