Id:
CVE-2016-4412
Comment
:
An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.
CVSSv2 Score:
3.6
Access vector:
|
NETWORK
|
Access complexity:
|
HIGH
|
Authentication:
|
SINGLE
|
Confidentiality impact:
|
PARTIAL
|
Integrity impact:
|
PARTIAL
|
Availability impact:
|
NONE
|
CVSSv2 Vector:
AV:N/AC:H/Au:S/C:P/I:P/A:N
CVSSv3 Score:
4.4
Attack vector:
|
NETWORK
|
Attack complexity:
|
HIGH
|
Privileges required:
|
LOW
|
User interaction:
|
REQUIRED
|
Scope:
|
CHANGED
|
Confidentiality impact:
|
LOW
|
Integrity impact:
|
LOW
|
Availability impact:
|
NONE
|
CVSSv3 Vector:
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
References: