Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-2206
Description:libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.2.2015.336   1.3.6.1.4.1.25623.1.0.111075   1.3.6.1.4.1.25623.1.0.703382   1.3.6.1.4.1.25623.1.0.869093   1.3.6.1.4.1.25623.1.0.869585   1.3.6.1.4.1.25623.1.0.869090  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-2206
BugTraq ID: 72949
http://www.securityfocus.com/bid/72949
Debian Security Information: DSA-3382 (Google Search)
http://www.debian.org/security/2015/dsa-3382
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151331.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151914.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151931.html
http://www.mandriva.com/security/advisories?name=MDVSA-2015:186
http://www.securitytracker.com/id/1031871
SuSE Security Announcement: openSUSE-SU-2015:1191 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-07/msg00008.html




© 1998-2025 E-Soft Inc. All rights reserved.