4.4

CVE-2016-4412

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

Data is provided by the National Vulnerability Database (NVD)
PhpmyadminPhpmyadmin Version4.0.0
PhpmyadminPhpmyadmin Version4.0.1
PhpmyadminPhpmyadmin Version4.0.2
PhpmyadminPhpmyadmin Version4.0.3
PhpmyadminPhpmyadmin Version4.0.4
PhpmyadminPhpmyadmin Version4.0.4.1
PhpmyadminPhpmyadmin Version4.0.4.2
PhpmyadminPhpmyadmin Version4.0.5
PhpmyadminPhpmyadmin Version4.0.6
PhpmyadminPhpmyadmin Version4.0.7
PhpmyadminPhpmyadmin Version4.0.8
PhpmyadminPhpmyadmin Version4.0.9
PhpmyadminPhpmyadmin Version4.0.10
PhpmyadminPhpmyadmin Version4.0.10.1
PhpmyadminPhpmyadmin Version4.0.10.2
PhpmyadminPhpmyadmin Version4.0.10.3
PhpmyadminPhpmyadmin Version4.0.10.4
PhpmyadminPhpmyadmin Version4.0.10.5
PhpmyadminPhpmyadmin Version4.0.10.6
PhpmyadminPhpmyadmin Version4.0.10.7
PhpmyadminPhpmyadmin Version4.0.10.8
PhpmyadminPhpmyadmin Version4.0.10.9
PhpmyadminPhpmyadmin Version4.0.10.10
PhpmyadminPhpmyadmin Version4.0.10.11
PhpmyadminPhpmyadmin Version4.0.10.12
PhpmyadminPhpmyadmin Version4.0.10.13
PhpmyadminPhpmyadmin Version4.0.10.14
PhpmyadminPhpmyadmin Version4.0.10.15
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.24% 0.469
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.4 1.3 2.7
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.6 3.9 4.9
AV:N/AC:H/Au:S/C:P/I:P/A:N