CVE-2016-6619: SQL Injection
An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6619?
CVE-2016-6619 has a severity rating that can allow an attacker to execute SQL injection attacks affecting the control user account.
How do I fix CVE-2016-6619?
To fix CVE-2016-6619, upgrade your phpMyAdmin installation to version 4.6.4 or later for 4.6.x, 4.4.15.8 or later for 4.4.x, or 4.0.10.17 or later for 4.0.x.
What versions are affected by CVE-2016-6619?
CVE-2016-6619 affects phpMyAdmin versions prior to 4.6.4 in the 4.6.x branch, 4.4.15.8 in the 4.4.x branch, and 4.0.10.17 in the 4.0.x branch.
Can CVE-2016-6619 be exploited remotely?
Yes, CVE-2016-6619 can be exploited remotely if a user can access the phpMyAdmin user interface.
What kind of attack is CVE-2016-6619 associated with?
CVE-2016-6619 is associated with SQL injection attacks that can compromise the control user account.