CVE-2016-6618: Medium severity phpmyadmin vulnerability
An issue was discovered in phpMyAdmin. The transformation feature allows a user to trigger a denial-of-service (DoS) attack against the server. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6618?
CVE-2016-6618 has a severity rating that indicates it is capable of causing denial-of-service (DoS) attacks against affected phpMyAdmin versions.
How do I fix CVE-2016-6618?
To fix CVE-2016-6618, upgrade phpMyAdmin to version 4.6.4 or later, 4.4.15.8 or later, or 4.0.10.17 or later.
Which versions of phpMyAdmin are affected by CVE-2016-6618?
CVE-2016-6618 affects phpMyAdmin versions 4.6.0 to 4.6.3, 4.4.0 to 4.4.15.7, and 4.0.0 to 4.0.10.16.
Can CVE-2016-6618 cause any data loss?
CVE-2016-6618 primarily results in denial of service, but it does not directly cause data loss.
Is CVE-2016-6618 a remote exploitation vulnerability?
Yes, CVE-2016-6618 can be exploited remotely if an attacker triggers the vulnerability through the transformation feature.