Description
phpMyAdmin 4.6.x before 4.6.3, when the environment lacks a PHP_SELF value, allows remote attackers to conduct cookie-attribute injection attacks via a crafted URI.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2006-3017)
IBM WebSEAL Improper Restriction of XML External Entity Reference Vulnerability (CVE-2019-4707)
WordPress Plugin Simple Ajax Shoutbox SQL Injection (2.2.1)
Drupal Core 8.6.x Multiple Vulnerabilities (8.6.0 - 8.6.1)
WordPress Plugin Custom Login Redirect Cross-Site Request Forgery (1.0.0)