CVE Vulnerabilities

CVE-2016-4412

Published: Dec 11, 2016 | Modified: Apr 12, 2025
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
3.6 LOW
AV:N/AC:H/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the users valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

Affected Software

NameVendorStart VersionEnd Version
PhpmyadminPhpmyadmin4.0.0 (including)4.0.0 (including)
PhpmyadminPhpmyadmin4.0.1 (including)4.0.1 (including)
PhpmyadminPhpmyadmin4.0.2 (including)4.0.2 (including)
PhpmyadminPhpmyadmin4.0.3 (including)4.0.3 (including)
PhpmyadminPhpmyadmin4.0.4 (including)4.0.4 (including)
PhpmyadminPhpmyadmin4.0.4.1 (including)4.0.4.1 (including)
PhpmyadminPhpmyadmin4.0.4.2 (including)4.0.4.2 (including)
PhpmyadminPhpmyadmin4.0.5 (including)4.0.5 (including)
PhpmyadminPhpmyadmin4.0.6 (including)4.0.6 (including)
PhpmyadminPhpmyadmin4.0.7 (including)4.0.7 (including)
PhpmyadminPhpmyadmin4.0.8 (including)4.0.8 (including)
PhpmyadminPhpmyadmin4.0.9 (including)4.0.9 (including)
PhpmyadminPhpmyadmin4.0.10 (including)4.0.10 (including)
PhpmyadminPhpmyadmin4.0.10.1 (including)4.0.10.1 (including)
PhpmyadminPhpmyadmin4.0.10.2 (including)4.0.10.2 (including)
PhpmyadminPhpmyadmin4.0.10.3 (including)4.0.10.3 (including)
PhpmyadminPhpmyadmin4.0.10.4 (including)4.0.10.4 (including)
PhpmyadminPhpmyadmin4.0.10.5 (including)4.0.10.5 (including)
PhpmyadminPhpmyadmin4.0.10.6 (including)4.0.10.6 (including)
PhpmyadminPhpmyadmin4.0.10.7 (including)4.0.10.7 (including)
PhpmyadminPhpmyadmin4.0.10.8 (including)4.0.10.8 (including)
PhpmyadminPhpmyadmin4.0.10.9 (including)4.0.10.9 (including)
PhpmyadminPhpmyadmin4.0.10.10 (including)4.0.10.10 (including)
PhpmyadminPhpmyadmin4.0.10.11 (including)4.0.10.11 (including)
PhpmyadminPhpmyadmin4.0.10.12 (including)4.0.10.12 (including)
PhpmyadminPhpmyadmin4.0.10.13 (including)4.0.10.13 (including)
PhpmyadminPhpmyadmin4.0.10.14 (including)4.0.10.14 (including)
PhpmyadminPhpmyadmin4.0.10.15 (including)4.0.10.15 (including)
PhpmyadminUbuntuartful*
PhpmyadminUbuntuesm-infra-legacy/trusty*
PhpmyadminUbuntuprecise*
PhpmyadminUbuntutrusty*
PhpmyadminUbuntutrusty/esm*
PhpmyadminUbuntuupstream*
PhpmyadminUbuntuyakkety*
PhpmyadminUbuntuzesty*

References