PT-2016-5209 · Phpmyadmin · Phpmyadmin

Published

2016-03-01

·

Updated

2024-06-15

·

CVE-2016-2562

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 4.5.x through 4.5.5.0
Description The issue concerns the checkHTTP function in the Config.class.php file, which fails to verify X.509 certificates from SSL servers, specifically those from api.github.com. This oversight allows man-in-the-middle attackers to spoof these servers, potentially obtaining sensitive information by using a crafted certificate.
Recommendations For phpMyAdmin versions 4.5.x through 4.5.5.0, update to version 4.5.5.1 or later to resolve the issue. As a temporary workaround, consider disabling the checkHTTP function until a patch is available. Restrict access to the Config.class.php file to minimize the risk of exploitation. Avoid using the checkHTTP function for verifying SSL connections until the issue is resolved.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-2562
GHSA-W8QG-J9FP-HRJF
OPENSUSE-SU-2024:10054-1

Affected Products

Phpmyadmin