Security Features in phpMyAdmin - CVE-2015-7873
Published: October 28, 2015 / Updated: July 28, 2020
Vulnerability identifier: #VU32372
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-7873
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
Affected software
phpMyAdmin
phpmyadmin (Alpine package)
php-udan11-sql-parser
phpMyAdmin
Fedora
phpmyadmin (Alpine package)
php-udan11-sql-parser
phpMyAdmin
Fedora
How to mitigate CVE-2015-7873
Install update from vendor's website.
phpMyAdmin - update to 4.4.15.1
phpmyadmin (Alpine package) - update to 4.4.15.1-r0
php-udan11-sql-parser - addressed in versions 3.0.4-1.fc21, 3.0.4-1.fc22, 3.0.4-1.fc23
phpMyAdmin - addressed in versions 4.4.15.1-1.el7, 4.5.1-1.fc21, 4.5.1-1.fc22, 4.5.1-1.fc23
phpmyadmin (Alpine package) - update to 4.4.15.1-r0
php-udan11-sql-parser - addressed in versions 3.0.4-1.fc21, 3.0.4-1.fc22, 3.0.4-1.fc23
phpMyAdmin - addressed in versions 4.4.15.1-1.el7, 4.5.1-1.fc21, 4.5.1-1.fc22, 4.5.1-1.fc23
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171311.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171326.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169987.html
- http://www.debian.org/security/2015/dsa-3382
- http://www.securityfocus.com/bid/77299
- http://www.securitytracker.com/id/1034013
- https://github.com/phpmyadmin/phpmyadmin/commit/cd097656758f981f80fb9029c7d6b4294582b706
- https://www.phpmyadmin.net/security/PMASA-2015-5/