GHSA-phhm-63xx-v9rr
Dashboard / Vulnerabilities / GHSA-phhm-63xx-v9rr
Summary: phpMyAdmin Reflected File Download attack
Details: An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicious SVG file. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
References: https://nvd.nist.gov/vuln/detail/CVE-2016-6628, https://github.com/phpmyadmin/composer, https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html, https://security.gentoo.org/glsa/201701-32, https://www.phpmyadmin.net/security/PMASA-2016-51, http://www.securityfocus.com/bid/92492
Affected packages
Package
Name: phpmyadmin/phpmyadmin
Purl: pkg:composer/phpmyadmin/phpmyadmin
Affected ranges
Type: ECOSYSTEM
Events:
