PT-2016-6651 · Phpmyadmin+1 · Phpmyadmin+1

Geeknik

·

Published

2016-07-03

·

Updated

2024-06-15

·

CVE-2016-5703

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 4.4.x through 4.4.15.6 phpMyAdmin versions 4.6.x through 4.6.2
Description The issue allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query. This occurs due to a SQL injection vulnerability in the libraries/central columns.lib.php file.
Recommendations For phpMyAdmin versions 4.4.x through 4.4.15.6, update to version 4.4.15.7 or later. For phpMyAdmin versions 4.6.x through 4.6.2, update to version 4.6.3 or later.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1758
CVE-2016-5703
MGASA-2016-0240
OPENSUSE-SU-2024:10054-1

Affected Products

Alt Linux
Phpmyadmin