CVE-2015-7873
published 2015-10-28CVE-2015-7873: The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
PriorityP425medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.62%
83.8th percentile
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:4.5.1-1 (bookworm) | phpmyadmin 4:4.5.1-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.5.1-1 | 4:4.5.1-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-7873: phpmyadmin - The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x...
vendor_debian·2015·CVSS 5.0
CVE-2015-7873 [MEDIUM] CVE-2015-7873: phpmyadmin - The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x...
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
Scope: local
bookworm: resolved (fixed in 4:4.5.1-1)
bullseye: resolved (fixed in 4:4.5.1-1)
forky: resolved (fixed in 4:4.5.1-1)
sid: resolved (fixed in 4:4.5.1-1)
trixie: resolved (fixed in 4:4.5.1-1)
Red Hat
phpMyAdmin: Content spoofing on url.php (PMASA-2015-5)
vendor_redhat·CVSS 5.0
CVE-2015-7873 [MEDIUM] phpMyAdmin: Content spoofing on url.php (PMASA-2015-5)
phpMyAdmin: Content spoofing on url.php (PMASA-2015-5)
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
GHSA
phpMyAdmin allows remote attackers to spoof content via the url parameter
ghsa·2022-05-17
CVE-2015-7873 [HIGH] CWE-20 phpMyAdmin allows remote attackers to spoof content via the url parameter
phpMyAdmin allows remote attackers to spoof content via the url parameter
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
OSV
phpMyAdmin allows remote attackers to spoof content via the url parameter
osv·2022-05-17
CVE-2015-7873 [HIGH] phpMyAdmin allows remote attackers to spoof content via the url parameter
phpMyAdmin allows remote attackers to spoof content via the url parameter
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
OSV
CVE-2015-7873: The redirection feature in url
osv·2015-10-28·CVSS 5.0
CVE-2015-7873 [MEDIUM] CVE-2015-7873: The redirection feature in url
The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171311.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171326.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169987.htmlhttp://www.debian.org/security/2015/dsa-3382http://www.securityfocus.com/bid/77299http://www.securitytracker.com/id/1034013https://github.com/phpmyadmin/phpmyadmin/commit/cd097656758f981f80fb9029c7d6b4294582b706https://www.phpmyadmin.net/security/PMASA-2015-5/http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171311.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171326.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169987.htmlhttp://www.debian.org/security/2015/dsa-3382http://www.securityfocus.com/bid/77299http://www.securitytracker.com/id/1034013https://github.com/phpmyadmin/phpmyadmin/commit/cd097656758f981f80fb9029c7d6b4294582b706https://www.phpmyadmin.net/security/PMASA-2015-5/
2015-10-28
Published