CVE-2015-8669
|
libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
Published:
December 26, 2015; 05:59:01 PM -05:00
|
V3.0: 5.3 MEDIUM
V2: 5.0 MEDIUM
|
CVE-2015-7873
|
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
Published:
October 28, 2015; 06:59:19 AM -04:00
|
V2: 5.0 MEDIUM
|
CVE-2015-6830
|
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha.
Published:
September 13, 2015; 09:59:08 PM -04:00
|
V2: 5.0 MEDIUM
|
CVE-2015-3903
|
libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Published:
May 26, 2015; 11:59:11 AM -04:00
|
V2: 4.3 MEDIUM
|
CVE-2015-3902
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.
Published:
May 26, 2015; 11:59:10 AM -04:00
|
V2: 6.8 MEDIUM
|