Description
phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.
References (7)
Core 7
Core References
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00013.html
Exploit, Patch x_refsource_misc
https://github.com/phpmyadmin/phpmyadmin/commit/240b8332db53dedc27baeec5306dabad3bdece3b
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/54488
Exploit, Patch x_refsource_misc
https://github.com/phpmyadmin/phpmyadmin/commit/24d0eb55203b029f250c77d63f2900ffbe099e8b
Vendor Advisory x_refsource_confirm
http://www.phpmyadmin.net/home_page/security/PMASA-2013-10.php
Patch x_refsource_misc
https://github.com/phpmyadmin/phpmyadmin/commit/66fe475d4f51b1761719cb0cab360748800373f7
Exploit, Patch x_refsource_misc
https://github.com/phpmyadmin/phpmyadmin/commit/da4042fb6c4365dc8187765c3bf525043687c66f
Scores
EPSS
0.0173
EPSS Percentile
82.5%
Details
CWE
CWE-20
Status
published
Products (22)
opensuse/opensuse
12.2
opensuse/opensuse
12.3
phpmyadmin/phpmyadmin
3.5.0.0
phpmyadmin/phpmyadmin
3.5.1.0
phpmyadmin/phpmyadmin
3.5.2.0
phpmyadmin/phpmyadmin
3.5.2.1
phpmyadmin/phpmyadmin
3.5.2.2
phpmyadmin/phpmyadmin
3.5.3.0
phpmyadmin/phpmyadmin
3.5.4
phpmyadmin/phpmyadmin
3.5.5
... and 12 more
Published
Aug 19, 2013
Tracked Since
Feb 18, 2026