Security Features in phpMyAdmin - CVE-2016-9851

 

Security Features in phpMyAdmin - CVE-2016-9851

Published: December 11, 2016 / Updated: August 4, 2020


Vulnerability identifier: #VU33572
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9851
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected.


Affected software

phpMyAdmin
phpmyadmin (Alpine package)

How to mitigate CVE-2016-9851

Install update from vendor's website.

phpmyadmin (Alpine package) - update to 4.4.15.9-r0

External References

Related Security Bulletins