CVE-2015-6830

phpMyAdmin 4.3.x-4.3.13.1 & 4.4.x-4.4.14.0 - Brute-Force Protection Bypass via reCaptcha

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-6830. PoCs published by Nikola Markovic.

AI-analyzed exploit summary This exploit targets a brute-force login bypass vulnerability in PHPMyAdmin versions >3.0 and <4.3.13.2/4.4.14.1. It attempts to authenticate as 'root' with a predefined password list by extracting and reusing session tokens.

Description

libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha.

Exploits (1)

exploitdb WORKING POC
by Nikola Markovic · pythonremotephp
https://www.exploit-db.com/exploits/52414

This exploit targets a brute-force login bypass vulnerability in PHPMyAdmin versions >3.0 and <4.3.13.2/4.4.14.1. It attempts to authenticate as 'root' with a predefined password list by extracting and reusing session tokens.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: PHPMyAdmin >3.0 & 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1
No auth needed
Prerequisites: Target URL with vulnerable PHPMyAdmin instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/76674
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3382
Patch, Vendor Advisory x_refsource_confirm
https://www.phpmyadmin.net/security/PMASA-2015-4/
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/166294.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/166531.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/166307.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033546

Scores

EPSS 0.2122
EPSS Percentile 95.8%

Details

CWE
CWE-200
Status published
Products (32)
phpmyadmin/phpmyadmin 4.3.0
phpmyadmin/phpmyadmin 4.3.1
phpmyadmin/phpmyadmin 4.3.2
phpmyadmin/phpmyadmin 4.3.3
phpmyadmin/phpmyadmin 4.3.4
phpmyadmin/phpmyadmin 4.3.5
phpmyadmin/phpmyadmin 4.3.6
phpmyadmin/phpmyadmin 4.3.7
phpmyadmin/phpmyadmin 4.3.8
phpmyadmin/phpmyadmin 4.3.9
... and 22 more
Published Sep 14, 2015
Tracked Since Feb 18, 2026