Command Injection in phpMyAdmin - CVE-2016-6609

 

Command Injection in phpMyAdmin - CVE-2016-6609

Published: December 11, 2016 / Updated: August 4, 2020


Vulnerability identifier: #VU33608
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6609
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to execute arbitrary code.

An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.


Affected software

phpMyAdmin
phpmyadmin (Alpine package)
Opensuse

How to mitigate CVE-2016-6609

Install update from vendor's website.

phpmyadmin (Alpine package) - update to 4.4.15.8-r0

External References

Related Security Bulletins