GHSA-567r-vqj7-5cw7
Dashboard / Vulnerabilities / GHSA-567r-vqj7-5cw7
Summary: phpMyAdmin Authentication Bypass
Details: An issue was discovered in phpMyAdmin involving the `$cfg['ArbitraryServerRegexp']` configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
References: https://nvd.nist.gov/vuln/detail/CVE-2016-6629, https://security.gentoo.org/glsa/201701-32, https://web.archive.org/web/20210725054025/http://www.securityfocus.com/bid/92493, https://www.phpmyadmin.net/security/PMASA-2016-52
Affected packages
Package
Name: phpmyadmin/phpmyadmin
Purl: pkg:composer/phpmyadmin/phpmyadmin
Affected ranges
Type: ECOSYSTEM
Events:
