First published: Sun Dec 11 2016(Updated: )
XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/phpmyadmin/phpmyadmin | >=4.6<4.6.4 | 4.6.4 |
PhpMyAdmin | =4.6.0 | |
PhpMyAdmin | =4.6.0-alpha1 | |
PhpMyAdmin | =4.6.0-rc1 | |
PhpMyAdmin | =4.6.0-rc2 | |
PhpMyAdmin | =4.6.1 | |
PhpMyAdmin | =4.6.2 | |
PhpMyAdmin | =4.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6608 has a medium severity rating due to the ability to execute XSS attacks through specially crafted database names.
To fix CVE-2016-6608, upgrade phpMyAdmin to version 4.6.4 or later.
All phpMyAdmin versions prior to 4.6.4, including 4.6.0, 4.6.1, 4.6.2, and 4.6.3, are affected by CVE-2016-6608.
CVE-2016-6608 can allow an attacker to execute XSS attacks through the database privilege check and the 'Remove partitioning' functionality.
There is no specific workaround for CVE-2016-6608; upgrading to a patched version is the recommended course of action.