CVE-2015-6830

EUVD-2022-5294
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
Affected Products (NVD)
VendorProductVersion
phpmyadminphpmyadmin
4.3.0
phpmyadminphpmyadmin
4.3.1
phpmyadminphpmyadmin
4.3.2
phpmyadminphpmyadmin
4.3.3
phpmyadminphpmyadmin
4.3.4
phpmyadminphpmyadmin
4.3.5
phpmyadminphpmyadmin
4.3.6
phpmyadminphpmyadmin
4.3.7
phpmyadminphpmyadmin
4.3.8
phpmyadminphpmyadmin
4.3.9
phpmyadminphpmyadmin
4.3.10
phpmyadminphpmyadmin
4.3.11
phpmyadminphpmyadmin
4.3.12
phpmyadminphpmyadmin
4.3.13.1
phpmyadminphpmyadmin
4.4.0
phpmyadminphpmyadmin
4.4.1
phpmyadminphpmyadmin
4.4.1.1
phpmyadminphpmyadmin
4.4.3
phpmyadminphpmyadmin
4.4.4
phpmyadminphpmyadmin
4.4.5
phpmyadminphpmyadmin
4.4.6
phpmyadminphpmyadmin
4.4.6.1
phpmyadminphpmyadmin
4.4.7
phpmyadminphpmyadmin
4.4.8
phpmyadminphpmyadmin
4.4.9
phpmyadminphpmyadmin
4.4.10
phpmyadminphpmyadmin
4.4.11
phpmyadminphpmyadmin
4.4.12
phpmyadminphpmyadmin
4.4.13
phpmyadminphpmyadmin
4.4.13.1
phpmyadminphpmyadmin
4.4.14
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
phpmyadmin
bookworm
4:5.2.1+dfsg-1
fixed
bullseye
4:5.0.4+dfsg2-2+deb11u1
fixed
jessie
no-dsa
sid
4:5.2.1+dfsg-4
fixed
squeeze
not-affected
trixie
4:5.2.1+dfsg-4
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
phpmyadmin
artful
not-affected
bionic
not-affected
precise
ignored
trusty
not-affected
vivid
Fixed 4:4.2.12-2+deb8u1build0.15.04.1
released
wily
ignored
xenial
not-affected
yakkety
not-affected
zesty
not-affected