Command Injection in phpMyAdmin - CVE-2016-6609
Published: December 11, 2016 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a remote authenticated user to execute arbitrary code.
An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected software
phpmyadmin (Alpine package)
Opensuse