CVE-2015-7873: Input Validation
Published Oct 28, 2015
·Updated
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
Affected Software
25 affected componentsFixes available
phpMyAdmin phpMyAdmin=4.4.0
phpMyAdmin phpMyAdmin=4.4.1
phpMyAdmin phpMyAdmin=4.4.1.1
phpMyAdmin phpMyAdmin=4.4.2
phpMyAdmin phpMyAdmin=4.4.3
phpMyAdmin phpMyAdmin=4.4.4
phpMyAdmin phpMyAdmin=4.4.5
phpMyAdmin phpMyAdmin=4.4.6
phpMyAdmin phpMyAdmin=4.4.6.1
phpMyAdmin phpMyAdmin=4.4.7
phpMyAdmin phpMyAdmin=4.4.8
phpMyAdmin phpMyAdmin=4.4.9
phpMyAdmin phpMyAdmin=4.4.10
phpMyAdmin phpMyAdmin=4.4.11
phpMyAdmin phpMyAdmin=4.4.12
phpMyAdmin phpMyAdmin=4.4.13
phpMyAdmin phpMyAdmin=4.4.13.1
phpMyAdmin phpMyAdmin=4.4.14
phpMyAdmin phpMyAdmin=4.4.14.1
phpMyAdmin phpMyAdmin=4.4.15
phpMyAdmin phpMyAdmin=4.5.0
phpMyAdmin phpMyAdmin=4.5.0.1
phpMyAdmin phpMyAdmin=4.5.0.2
composer/phpmyadmin/phpmyadmin>=4.5.0<4.5.1
4.5.1
composer/phpmyadmin/phpmyadmin>=4.4.0<4.4.15.1
4.4.15.1
Remediation
Patch Available
Event History
Oct 28, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
May 17, 2022
Advisory Published
via GitHub·03:25 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-7873?
CVE-2015-7873 is categorized as a moderate severity vulnerability.
2
How do I fix CVE-2015-7873?
To address CVE-2015-7873, upgrade phpMyAdmin to versions 4.4.15.1 or later, or 4.5.1 or later.
3
What software is affected by CVE-2015-7873?
CVE-2015-7873 affects phpMyAdmin versions 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1.
4
What type of vulnerability is CVE-2015-7873?
CVE-2015-7873 is a content spoofing vulnerability caused by the url parameter.
5
Can CVE-2015-7873 be exploited remotely?
Yes, CVE-2015-7873 can be exploited by remote attackers.