Description
phpMyAdmin 4.6.x before 4.6.3, when the environment lacks a PHP_SELF value, allows remote attackers to conduct cookie-attribute injection attacks via a crafted URI.
Remediation
References
Related Vulnerabilities
jQuery Validation Uncontrolled Resource Consumption Vulnerability (CVE-2021-21252)
WordPress Plugin user files Arbitrary File Upload (2.4.2)
Magento Cleartext Storage of Sensitive Information Vulnerability (CVE-2019-8118)
Apache HTTP Server Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-59775)