Commit Graph

6 Commits

Author SHA1 Message Date
Natanael Copa
afacb63805 community/phpmyadmin: upgrade to 4.7.1 2017-06-14 15:12:46 +00:00
Andy Postnikov
aeba1ff3b8 community/phpmyadmin: Upgrade to 4.7.0
Release notes https://www.phpmyadmin.net/news/2017/3/29/phpmyadmin-470-released/
2017-04-29 11:03:12 +00:00
Natanael Copa
4c4fe25d00 community/phpmyadmin: upgrade to 4.6.6 2017-01-27 14:34:06 +00:00
Sergey Lukin
517afce6b9 community/phpmyadmin: mistake fixed in secfixes info 2016-12-30 07:22:13 +00:00
Sergey Lukin
311ef72f19 community/phpmyadmin: security upgrade to 4.6.5.2 - fixes #6594
CVE-2016-9847: Unsafe generation of blowfish secret
CVE-2016-9848: phpinfo information leak value of sensitive (HttpOnly) cookies
CVE-2016-9849: Username deny rules bypass (AllowRoot & Others) by using Null Byte
CVE-2016-9850: Username rule matching issues
CVE-2016-9851: With a crafted request parameter value it is possible to bypass the logout timeout.
CVE-2016-9852 CVE-2016-9853 CVE-2016-9854 CVE-2016-9855: Multiple full path disclosure vulnerabilities
CVE-2016-9856 CVE-2016-9857: Multiple XSS vulnerabilities
CVE-2016-9858 CVE-2016-9859 CVE-2016-9860: We consider these vulnerabilities to be of moderate severity.
CVE-2016-9861: Bypass white-list protection for URL redirection
CVE-2016-9862: BBCode injection vulnerability
CVE-2016-9863: DOS vulnerability in table partitioning
CVE-2016-9864: Multiple SQL injection vulnerabilities
CVE-2016-9865: Incorrect serialized string parsing
CVE-2016-9866: CSRF token not stripped from the URL
2016-12-30 07:20:53 +00:00
Natanael Copa
a9b8bfa9d6 community/phpmyadmin: move form main
We don't want maintain this for more than 6 months due to the amount of
security issues.
2016-09-23 14:50:25 +00:00