CVE-2016-6611: SQL Injection
An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6611?
CVE-2016-6611 is considered a medium severity SQL injection vulnerability in phpMyAdmin.
How do I fix CVE-2016-6611?
To fix CVE-2016-6611, upgrade to phpMyAdmin version 4.6.4 or later, 4.4.15.8 or later, or 4.0.10.17 or later.
What versions of phpMyAdmin are affected by CVE-2016-6611?
All 4.6.x versions prior to 4.6.4, 4.4.x versions prior to 4.4.15.8, and 4.0.x versions prior to 4.0.10.17 are affected.
Can CVE-2016-6611 be exploited remotely?
Yes, CVE-2016-6611 can be exploited remotely through the export functionality of phpMyAdmin.
What is the nature of the attack in CVE-2016-6611?
CVE-2016-6611 involves an SQL injection attack that can be triggered by specially crafted database or table names.