CVE-2017-1000018 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-1000018): phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name CVE-2017-1000017 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-1000017): phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server CVE-2017-1000015 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-1000015): phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters CVE-2017-1000014 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-1000014): phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality CVE-2017-1000013 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-1000013): phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness
@Maintainer, could you please confirm if 4.0.x is vulnerable? In that case please call for stabilization when ready. Thank you
This bug is a duplicate of bug 614522. This was all addressed 6 months ago.
Thank you for the info Jorge. *** This bug has been marked as a duplicate of bug 614522 ***