Lucene search

K
freebsdFreeBSD00EC1BE1-22BB-11E6-9EAD-6805CA0B3D42
HistoryMay 25, 2016 - 12:00 a.m.

phpmyadmin -- XSS and sensitive data leakage

2016-05-2500:00:00
vuxml.freebsd.org
19

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.005

Percentile

77.2%

The phpmyadmin development team reports:

Description
Because user SQL queries are part of the URL, sensitive
information made as part of a user query can be exposed by
clicking on external links to attackers monitoring user GET
query parameters or included in the webserver logs.
Severity
We consider this to be non-critical.

Description
A specially crafted attack could allow for special HTML
characters to be passed as URL encoded values and displayed
back as special characters in the page.
Severity
We consider this to be non-critical.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchphpmyadmin= 4.6.0UNKNOWN
FreeBSDanynoarchphpmyadmin< 4.6.2UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.005

Percentile

77.2%