SB2016101814 - Cross-site scripting in phpmyadmin (Alpine package)
Published: October 18, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cross-site scripting (CVE-ID: CVE-2016-6608)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.
Remediation
Install update from vendor's website.