← Back

CVE-2015-3902

nvd nist
Published: May 26, 2015Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

Affected (56)

1 product
Phpmyadmin
Configuration A
56 vulnerable
Vulnerable SoftwareAffected Versions
Phpmyadmin
Version 4.0.0
Version 4.0.0 rc2
Version 4.0.0 rc3
Version 4.0.10.2
Version 4.0.10.5
Version 4.0.10.6
Version 4.0.10.7
Version 4.0.10.8
Version 4.0.10.9
Version 4.0.10
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4.1
Version 4.0.4.2
Version 4.0.4
Version 4.0.5
Version 4.0.6
Version 4.0.7
Version 4.0.8
Version 4.0.9
Version 4.2.0
Version 4.2.10.1
Version 4.2.11
Version 4.2.12
Version 4.2.13.1
Version 4.2.13.2
Version 4.2.1
Version 4.2.2
Version 4.2.3
Version 4.2.4
Version 4.2.5
Version 4.2.7.1
Version 4.2.7
Version 4.2.9.1
Version 4.3.0
Version 4.3.10
Version 4.3.11
Version 4.3.12
Version 4.3.13
Version 4.3.1
Version 4.3.2
Version 4.3.3
Version 4.3.4
Version 4.3.5
Version 4.3.6
Version 4.3.7
Version 4.3.8
Version 4.3.9
Version 4.4.0
Version 4.4.1.1
Version 4.4.1
Version 4.4.3
Version 4.4.4
Version 4.4.5
Version 4.4.6

Timeline

No history available yet.