ZeroHour

CVE-2016-5097

CVSS 3.0
5.3 medium
EPSS
1%p72
Published
()
Modified
Description

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.

Vendors
opensusephpmyadmin
Products
opensuse, phpmyadmin
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.