PhpMyAdmin bypass access restriction Vulnerability (CVE-2016-2039)
PhpMyAdmin bypass access restriction Vulnerability (CVE-2016-2039)
Release date:
Updated on:
Affected Systems:
PhpMyAdmin 4.5.4> 4.5.x
PhpMyAdmin 4.4.15.3> 4.4.x
PhpMyAdmin 4.0.10.13> 4.0.x
Description:
CVE (CAN) ID: CVE-2016-2039
Phpmyadmin is an online management tool for MySQL databases.
The CSRF token value is incorrectly generated in versions 4.0.x, 4.4.15.3, 4.4.4.x, and 4.5.4 before phpMyAdmin 4.0.10.13. Remote attackers can exploit this vulnerability to bypass the target access restriction by using the predicted value.
<* Source: Emanuel Bronshtein
*>
Suggestion:
Vendor patch:
PhpMyAdmin
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.phpmyadmin.net/home_page/security/PMASA-2016-2.php
This article permanently updates the link address: