CVE-2017-1000016
Published Jul 17, 2017
Last updated 7 years ago
Overview
- Description
- A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-20
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C641F362-D37D-47CB-BE6C-36E5F116F844" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85631B69-7060-42D1-AE24-466BA10EB390" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E62EDC79-47AA-4CED-AB7F-1E4D158EB653" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C0B800AA-6290-4032-AA17-21025A19C392" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "230D3D61-B090-49FA-91B1-9FA4DD2C6209" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33130418-95AC-41D2-B8B0-A107C9CABCFB" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22A5550C-91AC-41C3-AADF-1A7C02089E66" }, { "criteria": "cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F7A5E347-7A9D-4FAF-BDD2-314FA0A01821" } ], "operator": "OR" } ] } ]