Candidate: CVE-2015-7873 PublicDate: 2015-10-28 10:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7873 https://www.phpmyadmin.net/security/PMASA-2015-5/ Description: The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_phpmyadmin: upstream: https://github.com/phpmyadmin/phpmyadmin/commit/2b31866fe0b30b867aaf5b5fedb11adb354e037f (4.4) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/cd097656758f981f80fb9029c7d6b4294582b706 (4.5) upstream_phpmyadmin: released (4:4.5.1-1) precise_phpmyadmin: ignored (reached end-of-life) precise/esm_phpmyadmin: DNE (precise was needs-triage) trusty_phpmyadmin: not-affected (code not present) trusty/esm_phpmyadmin: not-affected (code not present) vivid_phpmyadmin: released (4:4.2.12-2+deb8u1build0.15.04.1) vivid/stable-phone-overlay_phpmyadmin: DNE vivid/ubuntu-core_phpmyadmin: DNE wily_phpmyadmin: ignored (reached end-of-life) xenial_phpmyadmin: not-affected (4:4.5.1-1) yakkety_phpmyadmin: not-affected (4:4.5.1-1) zesty_phpmyadmin: not-affected (4:4.5.1-1) artful_phpmyadmin: not-affected (4:4.5.1-1) bionic_phpmyadmin: not-affected (4:4.5.1-1) devel_phpmyadmin: not-affected (4:4.5.1-1)