Cross-site scripting in phpMyAdmin - CVE-2016-6608
Published: December 11, 2016 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.
Affected software
phpmyadmin (Alpine package)
Opensuse