CVE-2016-6632Phpmyadmin vulnerability

CWE-3995 documents4 sources
Severity
5.9MEDIUMNVD
EPSS
0.6%
top 31.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 17

Description

An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmin may not delete temporary files during the import of ESRI files. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

debiandebian/phpmyadmin< phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)
Packagistphpmyadmin/phpmyadmin4.64.6.4+2
Debianphpmyadmin/phpmyadmin< 4:4.6.4+dfsg1-1+3
NVDphpmyadmin/phpmyadmin60 versions+59

Patches

🔴Vulnerability Details

3
OSV
phpMyAdmin Denial of service (DOS) attack with dbase extension2022-05-17
GHSA
phpMyAdmin Denial of service (DOS) attack with dbase extension2022-05-17
OSV
CVE-2016-6632: An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmin may not delete temporary files during the import of ESRI files2016-12-11

📋Vendor Advisories

1
Debian
CVE-2016-6632: phpmyadmin - An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmi...2016