setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to conduct BBCode injection attacks against HTTP sessions via a crafted URI.
{ "binaries": [ { "binary_name": "phpmyadmin", "binary_version": "4:4.0.10-1ubuntu0.1+esm4" } ] }
{ "binaries": [ { "binary_name": "phpmyadmin", "binary_version": "4:4.5.4.1-2ubuntu2.1+esm6" } ] }