Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-3902

Опубликовано: 26 мая 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

РелизСтатусПримечание
artful

not-affected

4:4.4.6.1-1
bionic

not-affected

4:4.4.6.1-1
cosmic

not-affected

4:4.4.6.1-1
devel

not-affected

4:4.4.6.1-1
disco

not-affected

4:4.4.6.1-1
eoan

DNE

esm-apps/bionic

not-affected

4:4.4.6.1-1
esm-apps/focal

not-affected

4:4.4.6.1-1
esm-apps/jammy

not-affected

4:4.4.6.1-1
esm-apps/noble

not-affected

4:4.4.6.1-1

Показывать по

Ссылки на источники

EPSS

Процентиль: 39%
0.00166
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

nvd
около 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

debian
около 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the setu ...

github
около 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

EPSS

Процентиль: 39%
0.00166
Низкий

6.8 Medium

CVSS2