CVE-2016-6614: Path Traversal
An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6614?
CVE-2016-6614 is classified as a medium severity vulnerability due to its potential to allow unauthorized file system traversal.
How do I fix CVE-2016-6614?
To address CVE-2016-6614, upgrade to phpMyAdmin version 4.6.4 or later where the issue has been resolved.
What affected phpMyAdmin versions are impacted by CVE-2016-6614?
CVE-2016-6614 affects all phpMyAdmin versions prior to 4.6.4.
What are the implications of CVE-2016-6614 on my phpMyAdmin installation?
CVE-2016-6614 may allow attackers to manipulate file paths and access sensitive files on the server.
Is CVE-2016-6614 linked to any specific features in phpMyAdmin?
Yes, CVE-2016-6614 is related to the %u username replacement functionality within SaveDir and UploadDir features.