CVE-2015-2206

UnknownEPSS 3.26%

Last modified

CVE-2015-2206 is a vulnerability of currently unknown severity. libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.. EPSS estimates a 3.26% chance of exploitation in the next 30 days.

Description

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

Metrics

EPSS Probability
3.26%

86.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
FedoraprojectFedora20
FedoraprojectFedora21
FedoraprojectFedora22
PhpmyadminPhpmyadmin4.0.0
PhpmyadminPhpmyadmin4.0.1
PhpmyadminPhpmyadmin4.0.2
PhpmyadminPhpmyadmin4.0.3
PhpmyadminPhpmyadmin4.0.4
PhpmyadminPhpmyadmin4.0.4.1
PhpmyadminPhpmyadmin4.0.4.2
PhpmyadminPhpmyadmin4.0.5
PhpmyadminPhpmyadmin4.0.6
PhpmyadminPhpmyadmin4.0.7
PhpmyadminPhpmyadmin4.0.8
PhpmyadminPhpmyadmin4.0.9
PhpmyadminPhpmyadmin4.0.10
PhpmyadminPhpmyadmin4.0.10.1
PhpmyadminPhpmyadmin4.0.10.2
PhpmyadminPhpmyadmin4.0.10.3
PhpmyadminPhpmyadmin4.0.10.4
PhpmyadminPhpmyadmin4.0.10.5
PhpmyadminPhpmyadmin4.0.10.6
PhpmyadminPhpmyadmin4.0.10.7
PhpmyadminPhpmyadmin4.0.10.8
PhpmyadminPhpmyadmin4.2.0
PhpmyadminPhpmyadmin4.2.1
PhpmyadminPhpmyadmin4.2.2
PhpmyadminPhpmyadmin4.2.3
PhpmyadminPhpmyadmin4.2.4
PhpmyadminPhpmyadmin4.2.5
PhpmyadminPhpmyadmin4.2.6
PhpmyadminPhpmyadmin4.2.7
PhpmyadminPhpmyadmin4.2.7.1
PhpmyadminPhpmyadmin4.2.8
PhpmyadminPhpmyadmin4.2.8.1
PhpmyadminPhpmyadmin4.2.9
PhpmyadminPhpmyadmin4.2.9.1
PhpmyadminPhpmyadmin4.2.10
PhpmyadminPhpmyadmin4.2.10.1
PhpmyadminPhpmyadmin4.2.11
PhpmyadminPhpmyadmin4.2.12
PhpmyadminPhpmyadmin4.2.13
PhpmyadminPhpmyadmin4.2.13.1
PhpmyadminPhpmyadmin4.3.0
PhpmyadminPhpmyadmin4.3.1
PhpmyadminPhpmyadmin4.3.2
PhpmyadminPhpmyadmin4.3.3
PhpmyadminPhpmyadmin4.3.4
PhpmyadminPhpmyadmin4.3.5
PhpmyadminPhpmyadmin4.3.6

Showing 50 of 55 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-2206?
libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
How severe is CVE-2015-2206?
Severity scoring for CVE-2015-2206 is pending analysis. The EPSS model estimates a 3.26% probability of exploitation in the next 30 days.
How do I fix CVE-2015-2206?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-2206?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST