CVE-2016-6612: Infoleak
An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6612?
CVE-2016-6612 has been rated as a medium severity vulnerability due to its potential to expose sensitive files on the server.
How do I fix CVE-2016-6612?
To fix CVE-2016-6612, upgrade to phpMyAdmin version 4.0.10.17, 4.4.15.8, or 4.6.4 or higher.
Which versions of phpMyAdmin are affected by CVE-2016-6612?
All versions of phpMyAdmin 4.6.x prior to 4.6.4, 4.4.x prior to 4.4.15.8, and 4.0.x prior to 4.0.10.17 are affected by CVE-2016-6612.
What is the exploit vector for CVE-2016-6612?
CVE-2016-6612 can be exploited through the LOAD LOCAL INFILE functionality, allowing unauthorized file access.
Are there any known workarounds for CVE-2016-6612?
Disabling the LOAD LOCAL INFILE option in the MySQL configuration can serve as a temporary workaround for CVE-2016-6612.