CVE-2016-6607: XSS
XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS editor (certain fields in the graphical GIS editor are not properly escaped and can be used to trigger an XSS attack); Relation view; the following Transformations: Formatted, Imagelink, JPEG: Upload, RegexValidation, JPEG inline, PNG inline, and transformation wrapper; XML export; MediaWiki export; Designer; When the MySQL server is running with a specially-crafted logbin directive; Database tab; Replication feature; and Database search. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6607?
CVE-2016-6607 has been rated as medium severity due to its XSS vulnerabilities affecting multiple components of phpMyAdmin.
How do I fix CVE-2016-6607?
To fix CVE-2016-6607, update phpMyAdmin to the latest version where the XSS vulnerabilities have been addressed.
Which versions of phpMyAdmin are affected by CVE-2016-6607?
CVE-2016-6607 affects phpMyAdmin versions from 4.0.0 through 4.6.3.
What specific components are vulnerable in CVE-2016-6607?
CVE-2016-6607 includes vulnerabilities in the Zoom search, GIS editor, and Relation view components of phpMyAdmin.
Can CVE-2016-6607 be exploited remotely?
Yes, CVE-2016-6607 can be exploited remotely through crafted inputs that trigger XSS attacks.