Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.12.2021.4843.1
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-4843-1)
Summary:The remote host is missing an update for the 'phpmyadmin' package(s) announced via the USN-4843-1 advisory.
Description:Summary:
The remote host is missing an update for the 'phpmyadmin' package(s) announced via the USN-4843-1 advisory.

Vulnerability Insight:
Javier Nieto and Andres Rojas discovered that phpMyAdmin incorrectly
managed input in the form of passwords. An attacker could use this
vulnerability to cause a denial-of-service (DoS). This issue only
affected Ubuntu 14.04 ESM. (CVE-2014-9218)

Emanuel Bronshtein discovered that phpMyAdmin failed to properly sanitize
input in the form of database names in the PHP Array export feature.
An authenticated attacker could use this vulnerability to run arbitrary
PHP commands. This issue only affected Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
(CVE-2016-6609)

Emanuel Bronshtein discovered that phpMyAdmin failed to properly sanitize
input. An attacker could use this vulnerability to execute SQL injection
attacks. This issue only affected Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
(CVE-2016-6619)

Emanuel Bronshtein discovered that phpMyadmin failed to properly sanitize
input. An authenticated attacker could use this vulnerability to cause a
denial-of-service (DoS). This issue only affected Ubuntu 14.04 ESM and
Ubuntu 16.04 ESM. (CVE-2016-6630)

Emanuel Bronshtein discovered that phpMyAdmin failed to properly sanitize
input. An attacker could use this vulnerability to bypass AllowRoot
restrictions and deny rules for usernames. This issue only affected Ubuntu
14.04 ESM and Ubuntu 16.04 ESM. (CVE-2016-9849)

Emanuel Bronshtein discovered that phpMyAdmin would allow sensitive
information to be leaked when the argument separator in a URL was
not the default & value. An attacker could use this vulnerability to
obtain the CSRF token of a user. This issue only affected Ubuntu
14.04 ESM and Ubuntu 16.04 ESM. (CVE-2016-9866)

Isaac Bennetch discovered that phpMyAdmin was incorrectly restricting
user access due to the behavior of the substr function on some PHP
versions. An attacker could use this vulnerability to bypass login
restrictions established for users that have no password set. This
issue only affected Ubuntu 14.04 ESM. This issue only affected Ubuntu
14.04 ESM and Ubuntu 16.04 ESM. (CVE-2017-18264)

Emanuel Bronshtein discovered that phpMyAdmin failed to properly sanitize
input in the form of parameters sent during a table editing operation. An
attacker could use this vulnerability to trigger an endless recursion
and cause a denial-of-service (DoS). This issue only affected Ubuntu 14.04
ESM and Ubuntu 16.04 ESM. (CVE-2017-1000014)

Emanuel Bronshtein discovered that phpMyAdmin failed to properly sanitize
input used to generate a web page. An authenticated attacker could use this
vulnerability to execute CSS injection attacks. This issue only affected
Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. (CVE-2017-1000015)

It was discovered that phpMyAdmin incorrectly handled certain input. An
attacker could use this vulnerability to execute a cross-site scripting (XSS)
attack via a crafted URL. This issue only affected Ubuntu 16.04 ESM.
(CVE-2018-7260)

It was discovered phpMyAdmin incorrectly ... [Please see the references for more information on the vulnerabilities]

Affected Software/OS:
'phpmyadmin' package(s) on Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-9218
BugTraq ID: 71434
http://www.securityfocus.com/bid/71434
Debian Security Information: DSA-3382 (Google Search)
http://www.debian.org/security/2015/dsa-3382
http://www.mandriva.com/security/advisories?name=MDVSA-2014:243
XForce ISS Database: phpmyadmin-cve20149218-dos(99140)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99140
Common Vulnerability Exposure (CVE) ID: CVE-2016-6609
BugTraq ID: 94112
http://www.securityfocus.com/bid/94112
https://security.gentoo.org/glsa/201701-32
https://lists.debian.org/debian-lts-announce/2018/07/msg00006.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-6619
BugTraq ID: 95048
http://www.securityfocus.com/bid/95048
Common Vulnerability Exposure (CVE) ID: CVE-2016-6630
BugTraq ID: 92501
http://www.securityfocus.com/bid/92501
https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-9849
BugTraq ID: 94521
http://www.securityfocus.com/bid/94521
Common Vulnerability Exposure (CVE) ID: CVE-2016-9866
BugTraq ID: 94536
http://www.securityfocus.com/bid/94536
Common Vulnerability Exposure (CVE) ID: CVE-2017-1000014
BugTraq ID: 95721
http://www.securityfocus.com/bid/95721
Common Vulnerability Exposure (CVE) ID: CVE-2017-1000015
BugTraq ID: 95726
http://www.securityfocus.com/bid/95726
Common Vulnerability Exposure (CVE) ID: CVE-2017-18264
BugTraq ID: 97211
http://www.securityfocus.com/bid/97211
Common Vulnerability Exposure (CVE) ID: CVE-2018-12581
BugTraq ID: 104530
http://www.securityfocus.com/bid/104530
http://www.securitytracker.com/id/1041187
Common Vulnerability Exposure (CVE) ID: CVE-2018-19968
BugTraq ID: 106178
http://www.securityfocus.com/bid/106178
https://security.gentoo.org/glsa/201904-16
https://lists.debian.org/debian-lts-announce/2019/02/msg00003.html
Common Vulnerability Exposure (CVE) ID: CVE-2018-19970
BugTraq ID: 106181
http://www.securityfocus.com/bid/106181
Common Vulnerability Exposure (CVE) ID: CVE-2018-7260
BugTraq ID: 103099
http://www.securityfocus.com/bid/103099
https://udiniya.wordpress.com/2018/02/21/a-tale-of-stealing-session-cookie-in-phpmyadmin/
Common Vulnerability Exposure (CVE) ID: CVE-2019-11768
BugTraq ID: 108617
http://www.securityfocus.com/bid/108617
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/II4HC4QO6WUL2IRSQKCB66UBJOLLI5OV/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKJMYVXEDXGEGRO42T6H6VOEZJ65QPQ7/
SuSE Security Announcement: openSUSE-SU-2019:1689 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00005.html
SuSE Security Announcement: openSUSE-SU-2019:1861 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00017.html
Common Vulnerability Exposure (CVE) ID: CVE-2019-12616
BugTraq ID: 108619
http://www.securityfocus.com/bid/108619
http://packetstormsecurity.com/files/153251/phpMyAdmin-4.8-Cross-Site-Request-Forgery.html
https://www.phpmyadmin.net/security/
Common Vulnerability Exposure (CVE) ID: CVE-2019-12922
https://www.exploit-db.com/exploits/47385
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YCB3PTGHZ7AJCM6BKCQRRP6HG3OKYCMN/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QJ5BW2VEMD2P23ZYRWHDBEQHOKGKGWD6/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PBLBE6CSC2ZLINIRBUU5XBLXYVBTF3KA/
http://packetstormsecurity.com/files/154483/phpMyAdmin-4.9.0.1-Cross-Site-Request-Forgery.html
http://seclists.org/fulldisclosure/2019/Sep/23
https://github.com/phpmyadmin/phpmyadmin/commit/427fbed55d3154d96ecfc1c7784d49eaa3c04161
https://github.com/phpmyadmin/phpmyadmin/commit/7d21d4223bdbe0306593309132b4263d7087d13b
SuSE Security Announcement: openSUSE-SU-2019:2211 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00078.html
SuSE Security Announcement: openSUSE-SU-2020:0056 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00024.html
Common Vulnerability Exposure (CVE) ID: CVE-2019-19617
https://github.com/phpmyadmin/phpmyadmin/commit/1119de642b136d20e810bb20f545069a01dd7cc9
https://github.com/phpmyadmin/phpmyadmin/compare/RELEASE_4_9_1...RELEASE_4_9_2
https://www.phpmyadmin.net/news/2019/11/22/phpmyadmin-492-released/
https://lists.debian.org/debian-lts-announce/2019/12/msg00006.html
https://lists.debian.org/debian-lts-announce/2020/10/msg00024.html
Common Vulnerability Exposure (CVE) ID: CVE-2019-6798
BugTraq ID: 106727
http://www.securityfocus.com/bid/106727
Common Vulnerability Exposure (CVE) ID: CVE-2020-26934
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FHST4E5IJG7IKZTTW3R6MEZPVHJZ472K/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TNLGHVDNAEZEGRTUESSSQFM7MZTHIDQ5/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXK37YEHSDYCIPQSYEMN2OFTP2ZLM7DO/
https://security.gentoo.org/glsa/202101-35
https://www.phpmyadmin.net/security/PMASA-2020-5/
SuSE Security Announcement: openSUSE-SU-2020:1675 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00027.html
SuSE Security Announcement: openSUSE-SU-2020:1806 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00005.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-26935
https://advisory.checkmarx.net/advisory/CX-2020-4281
https://www.phpmyadmin.net/security/PMASA-2020-6/
Common Vulnerability Exposure (CVE) ID: CVE-2020-5504
https://cybersecurityworks.com/zerodays/cve-2020-5504-phpmyadmin.html
https://lists.debian.org/debian-lts-announce/2020/01/msg00011.html
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.