Description
libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
Remediation
References
Related Vulnerabilities
MySQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-8289)
WordPress Plugin File Browser, Manager, Backup (+ Database) Security Bypass (1.23)
WordPress Plugin Mail On Update Cross-Site Request Forgery (5.1.0)
WordPress 2.1.1 Cross-Site Scripting Vulnerability (2.1.1)
WordPress Plugin Really Simple Guest Post Local File Inclusion (1.0.6)