CVE-2016-5097

Source
https://cve.org/CVERecord?id=CVE-2016-5097
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5097.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-5097
Downstream
Related
Published
2016-07-05T01:59:05.673Z
Modified
2026-07-08T05:48:28.493654205Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*"
            ],
            "vendor_product": "opensuse:opensuse",
            "extracted_events": [
                {
                    "introduced": "13.1"
                },
                {
                    "last_affected": "13.1"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/phpmyadmin/phpmyadmin

Affected ranges

Type
GIT
Repo
https://github.com/phpmyadmin/phpmyadmin
Events
Database specific
{
    "cpe": "cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.6.1"
        }
    ]
}

Affected versions

Other
RELEASE_2_2_0
RELEASE_2_2_1
RELEASE_2_2_2
RELEASE_2_2_3
RELEASE_2_2_4
RELEASE_2_2_5
RELEASE_2_2_6
RELEASE_2_2_7PL1
RELEASE_2_3_0
RELEASE_2_3_1
RELEASE_2_3_2
RELEASE_2_3_3PL1
RELEASE_2_4_0
RELEASE_2_5_0
RELEASE_2_5_1
RELEASE_2_5_2
RELEASE_2_5_4
RELEASE_2_5_5PL1
RELEASE_2_5_6
RELEASE_2_5_7PL1
RELEASE_2_6_1PL3
RELEASE_2_6_2PL1
RELEASE_2_6_3PL1
RELEASE_2_6_4PL4
RELEASE_2_7_0PL2
RELEASE_2_8_0_4
RELEASE_2_8_1
RELEASE_2_8_2_4
RELEASE_2_9_0
RELEASE_3_4_0RC2
RELEASE_3_5_0ALPHA1
RELEASE_4_0_0ALPHA2
RELEASE_4_0_0BETA3
RELEASE_4_0_0RC1
RELEASE_4_1_0ALPHA1
RELEASE_4_1_0BETA1
RELEASE_4_1_0BETA2
RELEASE_4_2_0ALPHA2
RELEASE_4_2_0BETA1
RELEASE_4_6_0ALPHA1
RELEASE_4_6_0RC2
RELEASE_4_6_1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5097.json"