5
CVSSv2

CVE-2015-7873

Published: 28/10/2015 Updated: 07/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The redirection feature in url.php in phpMyAdmin 4.4.x prior to 4.4.15.1 and 4.5.x prior to 4.5.1 allows remote malicious users to spoof content via the url parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 4.4.0

phpmyadmin phpmyadmin 4.4.1

phpmyadmin phpmyadmin 4.4.6.1

phpmyadmin phpmyadmin 4.4.7

phpmyadmin phpmyadmin 4.4.13.1

phpmyadmin phpmyadmin 4.4.14

phpmyadmin phpmyadmin 4.4.1.1

phpmyadmin phpmyadmin 4.4.2

phpmyadmin phpmyadmin 4.4.8

phpmyadmin phpmyadmin 4.4.9

phpmyadmin phpmyadmin 4.4.14.1

phpmyadmin phpmyadmin 4.4.15

phpmyadmin phpmyadmin 4.5.0

phpmyadmin phpmyadmin 4.4.3

phpmyadmin phpmyadmin 4.4.4

phpmyadmin phpmyadmin 4.4.10

phpmyadmin phpmyadmin 4.4.11

phpmyadmin phpmyadmin 4.5.0.1

phpmyadmin phpmyadmin 4.5.0.2

phpmyadmin phpmyadmin 4.4.5

phpmyadmin phpmyadmin 4.4.6

phpmyadmin phpmyadmin 4.4.12

phpmyadmin phpmyadmin 4.4.13

Vendor Advisories

Several issues have been fixed in phpMyAdmin, the web administration tool for MySQL CVE-2014-8958 (Wheezy only) Multiple cross-site scripting (XSS) vulnerabilities CVE-2014-9218 (Wheezy only) Denial of service (resource consumption) via a long password CVE-2015-2206 Risk of BREACH attack due to reflected parameter CVE-2015- ...