5.3
CVE-2016-9847
- EPSS 0.43%
- Published 11.12.2016 02:59:44
- Last modified 12.04.2025 10:46:40
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpMyAdmin generates one at runtime. A vulnerability was reported where the way this value is created uses a weak algorithm. This could allow an attacker to determine the user's blowfish_secret and potentially decrypt their cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Data is provided by the National Vulnerability Database (NVD)
Phpmyadmin ≫ Phpmyadmin Version4.6.0
Phpmyadmin ≫ Phpmyadmin Version4.6.1
Phpmyadmin ≫ Phpmyadmin Version4.6.2
Phpmyadmin ≫ Phpmyadmin Version4.6.3
Phpmyadmin ≫ Phpmyadmin Version4.6.4
Phpmyadmin ≫ Phpmyadmin Version4.0.0
Phpmyadmin ≫ Phpmyadmin Version4.0.1
Phpmyadmin ≫ Phpmyadmin Version4.0.2
Phpmyadmin ≫ Phpmyadmin Version4.0.3
Phpmyadmin ≫ Phpmyadmin Version4.0.4
Phpmyadmin ≫ Phpmyadmin Version4.0.4.1
Phpmyadmin ≫ Phpmyadmin Version4.0.4.2
Phpmyadmin ≫ Phpmyadmin Version4.0.5
Phpmyadmin ≫ Phpmyadmin Version4.0.6
Phpmyadmin ≫ Phpmyadmin Version4.0.7
Phpmyadmin ≫ Phpmyadmin Version4.0.8
Phpmyadmin ≫ Phpmyadmin Version4.0.9
Phpmyadmin ≫ Phpmyadmin Version4.0.10
Phpmyadmin ≫ Phpmyadmin Version4.0.10.1
Phpmyadmin ≫ Phpmyadmin Version4.0.10.2
Phpmyadmin ≫ Phpmyadmin Version4.0.10.3
Phpmyadmin ≫ Phpmyadmin Version4.0.10.4
Phpmyadmin ≫ Phpmyadmin Version4.0.10.5
Phpmyadmin ≫ Phpmyadmin Version4.0.10.6
Phpmyadmin ≫ Phpmyadmin Version4.0.10.7
Phpmyadmin ≫ Phpmyadmin Version4.0.10.8
Phpmyadmin ≫ Phpmyadmin Version4.0.10.9
Phpmyadmin ≫ Phpmyadmin Version4.0.10.10
Phpmyadmin ≫ Phpmyadmin Version4.0.10.11
Phpmyadmin ≫ Phpmyadmin Version4.0.10.12
Phpmyadmin ≫ Phpmyadmin Version4.0.10.13
Phpmyadmin ≫ Phpmyadmin Version4.0.10.14
Phpmyadmin ≫ Phpmyadmin Version4.0.10.15
Phpmyadmin ≫ Phpmyadmin Version4.0.10.16
Phpmyadmin ≫ Phpmyadmin Version4.0.10.17
Phpmyadmin ≫ Phpmyadmin Version4.4.0
Phpmyadmin ≫ Phpmyadmin Version4.4.1
Phpmyadmin ≫ Phpmyadmin Version4.4.1.1
Phpmyadmin ≫ Phpmyadmin Version4.4.2
Phpmyadmin ≫ Phpmyadmin Version4.4.3
Phpmyadmin ≫ Phpmyadmin Version4.4.4
Phpmyadmin ≫ Phpmyadmin Version4.4.5
Phpmyadmin ≫ Phpmyadmin Version4.4.6
Phpmyadmin ≫ Phpmyadmin Version4.4.6.1
Phpmyadmin ≫ Phpmyadmin Version4.4.7
Phpmyadmin ≫ Phpmyadmin Version4.4.8
Phpmyadmin ≫ Phpmyadmin Version4.4.9
Phpmyadmin ≫ Phpmyadmin Version4.4.10
Phpmyadmin ≫ Phpmyadmin Version4.4.11
Phpmyadmin ≫ Phpmyadmin Version4.4.12
Phpmyadmin ≫ Phpmyadmin Version4.4.13
Phpmyadmin ≫ Phpmyadmin Version4.4.13.1
Phpmyadmin ≫ Phpmyadmin Version4.4.14
Phpmyadmin ≫ Phpmyadmin Version4.4.14.1
Phpmyadmin ≫ Phpmyadmin Version4.4.15
Phpmyadmin ≫ Phpmyadmin Version4.4.15.1
Phpmyadmin ≫ Phpmyadmin Version4.4.15.2
Phpmyadmin ≫ Phpmyadmin Version4.4.15.3
Phpmyadmin ≫ Phpmyadmin Version4.4.15.4
Phpmyadmin ≫ Phpmyadmin Version4.4.15.5
Phpmyadmin ≫ Phpmyadmin Version4.4.15.6
Phpmyadmin ≫ Phpmyadmin Version4.4.15.7
Phpmyadmin ≫ Phpmyadmin Version4.4.15.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.43% | 0.618 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|