CVE-2016-5701: Code Injection
setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to conduct BBCode injection attacks against HTTP sessions via a crafted URI.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5701?
CVE-2016-5701 is classified as a medium severity vulnerability due to its potential to allow BBCode injection attacks.
How do I fix CVE-2016-5701?
To fix CVE-2016-5701, you should upgrade phpMyAdmin to version 4.0.10.16 or later, 4.4.15.7 or later, or 4.6.3 or later.
What systems are affected by CVE-2016-5701?
CVE-2016-5701 affects phpMyAdmin versions 4.0.0 to 4.0.10.15, 4.4.0 to 4.4.15.6, and 4.6.0 to 4.6.2.
What kind of attacks can be performed due to CVE-2016-5701?
Due to CVE-2016-5701, attackers can conduct BBCode injection attacks leading to potential manipulation of HTTP sessions.
Is there a patch available for CVE-2016-5701?
Yes, there are patches available in the updated versions of phpMyAdmin that resolve the vulnerability CVE-2016-5701.