An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-757-1 | phpmyadmin security update |
EUVD |
EUVD-2016-5412 | An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T00:25:14.478Z
Reserved: 2016-04-30T00:00:00
Link: CVE-2016-4412
No data.
Status : Deferred
Published: 2016-12-11T02:59:09.030
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-4412
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD