CVE-2017-1000017

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
17/07/2017
Last modified:
20/04/2025

Description

phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* 4.0.0 (including) 4.0.10.19 (excluding)
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* 4.4.0 (including) 4.4.15.10 (including)
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* 4.6.0 (including) 4.6.6 (including)