CVE-2016-5097

Source
https://cve.org/CVERecord?id=CVE-2016-5097
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-5097.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-5097
Downstream
Related
Published
2016-07-05T01:59:05Z
Modified
2026-05-17T11:55:14Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.

Database specific
{
    "unresolved_ranges":  [
        {
            "cpes":  [
                "cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "last_affected":  "13.1"
                }
            ],
            "source":  "CPE_FIELD",
            "vendor_product":  "opensuse:opensuse"
        }
    ]
}
References

Affected packages