Wind River Support Network

HomeDefectsLIN7-7221
Acknowledged

LIN7-7221 : Security Advisory - phpmyadmin - CVE-2016-6629

Created: Dec 15, 2016    Updated: May 29, 2018
Found In Version: 7.0.0.21
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-6629

CVEs


Live chat
Online