VulnerabilityModified
CVE-2014-9218
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.
MEDIUM 5.0EPSS 10.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 10.73% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- phpmyadmin/phpmyadmin
- Source
- cve@mitre.org
References
- http://www.debian.org/security/2015/dsa-3382
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:243
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-17.php
- http://www.securityfocus.com/bid/71434
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99140
- https://github.com/phpmyadmin/phpmyadmin/commit/095729d81205f15f40d216d25917017da4c2fff8Exploit
- https://github.com/phpmyadmin/phpmyadmin/commit/1ac863c7573d12012374d5d41e5c7dc5505ea6e1Exploit
- https://github.com/phpmyadmin/phpmyadmin/commit/62b2c918d26cc78d1763945e3d44d1a63294a819Exploit
- http://www.debian.org/security/2015/dsa-3382
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:243
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-17.php
- http://www.securityfocus.com/bid/71434
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99140
- https://github.com/phpmyadmin/phpmyadmin/commit/095729d81205f15f40d216d25917017da4c2fff8Exploit
- https://github.com/phpmyadmin/phpmyadmin/commit/1ac863c7573d12012374d5d41e5c7dc5505ea6e1Exploit
- https://github.com/phpmyadmin/phpmyadmin/commit/62b2c918d26cc78d1763945e3d44d1a63294a819Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.