An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
https://www.phpmyadmin.net/security/PMASA-2016-62 | patch vendor advisory |
https://security.gentoo.org/glsa/201701-32 | vendor advisory |
http://www.securityfocus.com/bid/94534 | vdb entry third party advisory |