CVE-2016-6620: Critical severity phpmyadmin vulnerability
An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object instantiation and autoloading. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6620?
CVE-2016-6620 has a high severity due to the potential for remote code execution.
How do I fix CVE-2016-6620?
To fix CVE-2016-6620, upgrade phpMyAdmin to version 4.6.4 or later.
What components are affected by CVE-2016-6620?
CVE-2016-6620 affects all phpMyAdmin versions prior to 4.6.4.
What is the attack vector for CVE-2016-6620?
The attack vector for CVE-2016-6620 is the use of the PHP unserialize() function with unverified input.
Are there any workarounds for CVE-2016-6620?
There are no known workarounds for CVE-2016-6620; updating to the latest version is recommended.