320
VMScore

CVE-2016-4412

Published: 11/12/2016 Updated: 01/07/2017
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.4 | Impact Score: 2.7 | Exploitability Score: 1.3
VMScore: 320
Vector: AV:N/AC:H/Au:S/C:P/I:P/A:N

Vulnerability Summary

An issue exists in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (before 4.0.10.16) are affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin 4.0.0

phpmyadmin phpmyadmin 4.0.1

phpmyadmin phpmyadmin 4.0.2

phpmyadmin phpmyadmin 4.0.7

phpmyadmin phpmyadmin 4.0.8

phpmyadmin phpmyadmin 4.0.10.5

phpmyadmin phpmyadmin 4.0.10.6

phpmyadmin phpmyadmin 4.0.10.13

phpmyadmin phpmyadmin 4.0.10.14

phpmyadmin phpmyadmin 4.0.10.15

phpmyadmin phpmyadmin 4.0.5

phpmyadmin phpmyadmin 4.0.6

phpmyadmin phpmyadmin 4.0.10.3

phpmyadmin phpmyadmin 4.0.10.4

phpmyadmin phpmyadmin 4.0.10.11

phpmyadmin phpmyadmin 4.0.10.12

phpmyadmin phpmyadmin 4.0.3

phpmyadmin phpmyadmin 4.0.4

phpmyadmin phpmyadmin 4.0.9

phpmyadmin phpmyadmin 4.0.10

phpmyadmin phpmyadmin 4.0.10.7

phpmyadmin phpmyadmin 4.0.10.8

phpmyadmin phpmyadmin 4.0.4.1

phpmyadmin phpmyadmin 4.0.4.2

phpmyadmin phpmyadmin 4.0.10.1

phpmyadmin phpmyadmin 4.0.10.2

phpmyadmin phpmyadmin 4.0.10.9

phpmyadmin phpmyadmin 4.0.10.10