First published: Tue Jul 05 2016(Updated: )
Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin | =4.4.0 | |
phpMyAdmin | =4.4.1 | |
phpMyAdmin | =4.4.1.1 | |
phpMyAdmin | =4.4.2 | |
phpMyAdmin | =4.4.3 | |
phpMyAdmin | =4.4.4 | |
phpMyAdmin | =4.4.5 | |
phpMyAdmin | =4.4.6 | |
phpMyAdmin | =4.4.6.1 | |
phpMyAdmin | =4.4.7 | |
phpMyAdmin | =4.4.8 | |
phpMyAdmin | =4.4.9 | |
phpMyAdmin | =4.4.10 | |
phpMyAdmin | =4.4.11 | |
phpMyAdmin | =4.4.12 | |
phpMyAdmin | =4.4.13 | |
phpMyAdmin | =4.4.13.1 | |
phpMyAdmin | =4.4.14.1 | |
phpMyAdmin | =4.4.15 | |
phpMyAdmin | =4.4.15.1 | |
phpMyAdmin | =4.4.15.2 | |
phpMyAdmin | =4.4.15.3 | |
phpMyAdmin | =4.4.15.4 | |
phpMyAdmin | =4.4.15.5 | |
SUSE Linux | =13.1 | |
phpMyAdmin | =4.6.0 | |
phpMyAdmin | =4.6.0-alpha1 | |
phpMyAdmin | =4.6.0-rc1 | |
phpMyAdmin | =4.6.0-rc2 | |
phpMyAdmin | =4.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5099 has a moderate severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2016-5099, upgrade phpMyAdmin to version 4.4.15.6 or later, or 4.6.2 or later.
CVE-2016-5099 affects phpMyAdmin versions 4.4.0 to 4.4.15.5 and 4.6.0 to 4.6.1.
CVE-2016-5099 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2016-5099 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.