The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade phpmyadmin | Sep 20, 2017 | Oct 28, 2015 |
| Debian | — | Upgrade phpmyadmin | Nov 9, 2015 | Oct 28, 2015 |
| Freebsd | — | Upgrade phpMyAdmin | Dec 10, 2025 | Oct 23, 2015 |
| Phpmyadmin | — | Upgrade phpMyAdmin to the latest version | May 4, 2017 | Oct 28, 2015 |
| Suse | — | Upgrade phpmyadmin | Dec 18, 2015 | Oct 28, 2015 |
| Ubuntu | — | Upgrade phpmyadmin | Nov 19, 2024 | Oct 28, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub