Description
The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Meta and Date Remover Cross-Site Request Forgery (1.7.5)
WordPress Plugin Share, Print and PDF Products for WooCommerce Security Bypass (2.7.2)
Microsoft SQL Server Other Vulnerability (CVE-2000-1085)
WordPress Plugin myEASYbackup 'dwn_file' Parameter Directory Traversal (1.0.8.1)