CVE Vulnerabilities

CVE-2016-4412

Published: Dec 11, 2016 | Modified: Jul 01, 2017
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
3.6 LOW
AV:N/AC:H/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the users valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

Affected Software

Name Vendor Start Version End Version
Phpmyadmin Phpmyadmin 4.0.0 (including) 4.0.0 (including)
Phpmyadmin Phpmyadmin 4.0.1 (including) 4.0.1 (including)
Phpmyadmin Phpmyadmin 4.0.2 (including) 4.0.2 (including)
Phpmyadmin Phpmyadmin 4.0.3 (including) 4.0.3 (including)
Phpmyadmin Phpmyadmin 4.0.4 (including) 4.0.4 (including)
Phpmyadmin Phpmyadmin 4.0.4.1 (including) 4.0.4.1 (including)
Phpmyadmin Phpmyadmin 4.0.4.2 (including) 4.0.4.2 (including)
Phpmyadmin Phpmyadmin 4.0.5 (including) 4.0.5 (including)
Phpmyadmin Phpmyadmin 4.0.6 (including) 4.0.6 (including)
Phpmyadmin Phpmyadmin 4.0.7 (including) 4.0.7 (including)
Phpmyadmin Phpmyadmin 4.0.8 (including) 4.0.8 (including)
Phpmyadmin Phpmyadmin 4.0.9 (including) 4.0.9 (including)
Phpmyadmin Phpmyadmin 4.0.10 (including) 4.0.10 (including)
Phpmyadmin Phpmyadmin 4.0.10.1 (including) 4.0.10.1 (including)
Phpmyadmin Phpmyadmin 4.0.10.2 (including) 4.0.10.2 (including)
Phpmyadmin Phpmyadmin 4.0.10.3 (including) 4.0.10.3 (including)
Phpmyadmin Phpmyadmin 4.0.10.4 (including) 4.0.10.4 (including)
Phpmyadmin Phpmyadmin 4.0.10.5 (including) 4.0.10.5 (including)
Phpmyadmin Phpmyadmin 4.0.10.6 (including) 4.0.10.6 (including)
Phpmyadmin Phpmyadmin 4.0.10.7 (including) 4.0.10.7 (including)
Phpmyadmin Phpmyadmin 4.0.10.8 (including) 4.0.10.8 (including)
Phpmyadmin Phpmyadmin 4.0.10.9 (including) 4.0.10.9 (including)
Phpmyadmin Phpmyadmin 4.0.10.10 (including) 4.0.10.10 (including)
Phpmyadmin Phpmyadmin 4.0.10.11 (including) 4.0.10.11 (including)
Phpmyadmin Phpmyadmin 4.0.10.12 (including) 4.0.10.12 (including)
Phpmyadmin Phpmyadmin 4.0.10.13 (including) 4.0.10.13 (including)
Phpmyadmin Phpmyadmin 4.0.10.14 (including) 4.0.10.14 (including)
Phpmyadmin Phpmyadmin 4.0.10.15 (including) 4.0.10.15 (including)
Phpmyadmin Ubuntu artful *
Phpmyadmin Ubuntu esm-infra-legacy/trusty *
Phpmyadmin Ubuntu precise *
Phpmyadmin Ubuntu trusty *
Phpmyadmin Ubuntu trusty/esm *
Phpmyadmin Ubuntu upstream *
Phpmyadmin Ubuntu yakkety *
Phpmyadmin Ubuntu zesty *

References