CVE-2016-6608
published 2016-12-11CVE-2016-6608: XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database…
PriorityP428medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.28%
66.8th percentile
XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:4.6.4+dfsg1-1 (bookworm) | phpmyadmin 4:4.6.4+dfsg1-1 (bookworm) |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | — | — |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.6.4+dfsg1-1 | 4:4.6.4+dfsg1-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.6.4+dfsg1-1 | 4:4.6.4+dfsg1-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.6.4+dfsg1-1 | 4:4.6.4+dfsg1-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:4.6.4+dfsg1-1 | 4:4.6.4+dfsg1-1 |
| phpmyadmin | phpmyadmin | >= 4.6 < 4.6.4 | 4.6.4 |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
phpMyAdmin Cross-site Scripting (XSS)
ghsa·2022-05-17
CVE-2016-6608 [MEDIUM] CWE-79 phpMyAdmin Cross-site Scripting (XSS)
phpMyAdmin Cross-site Scripting (XSS)
XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.
OSV
phpMyAdmin Cross-site Scripting (XSS)
osv·2022-05-17
CVE-2016-6608 [MEDIUM] phpMyAdmin Cross-site Scripting (XSS)
phpMyAdmin Cross-site Scripting (XSS)
XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.
OSV
CVE-2016-6608: XSS issues were discovered in phpMyAdmin
osv·2016-12-11·CVSS 6.1
CVE-2016-6608 [MEDIUM] CVE-2016-6608: XSS issues were discovered in phpMyAdmin
XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.
Debian
CVE-2016-6608: phpmyadmin - XSS issues were discovered in phpMyAdmin. This affects the database privilege ch...
vendor_debian·2016·CVSS 6.1
CVE-2016-6608 [MEDIUM] CVE-2016-6608: phpmyadmin - XSS issues were discovered in phpMyAdmin. This affects the database privilege ch...
XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.
Scope: local
bookworm: resolved (fixed in 4:4.6.4+dfsg1-1)
bullseye: resolved (fixed in 4:4.6.4+dfsg1-1)
forky: resolved (fixed in 4:4.6.4+dfsg1-1)
sid: resolved (fixed in 4:4.6.4+dfsg1-1)
trixie: resolved (fixed in 4:4.6.4+dfsg1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-12-11
Published