Security Advisory

CVE-2016-6629

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2016-12-11 02:00:00
Last updated 2024-08-06 01:36:29
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.