cbcvebase.
CVE-2016-6617
published 2016-12-11

CVE-2016-6617: An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export…

PriorityP345high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
1.51%
71.5th percentile
An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4) are affected.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianphpmyadmin< phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)
phpmyadminphpmyadmin
phpmyadminphpmyadmin
phpmyadminphpmyadmin
phpmyadminphpmyadmin
phpmyadminphpmyadmin>= 0 < 4:4.6.4+dfsg1-14:4.6.4+dfsg1-1
phpmyadminphpmyadmin>= 0 < 4:4.6.4+dfsg1-14:4.6.4+dfsg1-1
phpmyadminphpmyadmin>= 0 < 4:4.6.4+dfsg1-14:4.6.4+dfsg1-1
phpmyadminphpmyadmin>= 0 < 4:4.6.4+dfsg1-14:4.6.4+dfsg1-1

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.