CVE-2016-6633Code Injection in Phpmyadmin

CWE-94Code Injection6 documents5 sources
Severity
8.1HIGHNVD
EPSS
1.8%
top 17.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 17

Description

An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remote code execution attack against certain PHP installations that are running with the dbase extension. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages4 packages

debiandebian/phpmyadmin< phpmyadmin 4:4.6.4+dfsg1-1 (bookworm)
Packagistphpmyadmin/phpmyadmin4.64.6.4+2
Debianphpmyadmin/phpmyadmin< 4:4.6.4+dfsg1-1+3
NVDphpmyadmin/phpmyadmin60 versions+59

Patches

🔴Vulnerability Details

3
OSV
phpMyAdmin Remote code execution vulnerability when PHP is running with dbase extension2022-05-17
GHSA
phpMyAdmin Remote code execution vulnerability when PHP is running with dbase extension2022-05-17
OSV
CVE-2016-6633: An issue was discovered in phpMyAdmin2016-12-11

📋Vendor Advisories

1
Debian
CVE-2016-6633: phpmyadmin - An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remot...2016

💬Community

1
Bugzilla
CVE-2016-4029 CVE-2016-6634 CVE-2016-6635 wordpress: 4.5 release security fixes2016-08-08