CVE-2016-6624: Medium severity phpmyadmin vulnerability
An issue was discovered in phpMyAdmin involving improper enforcement of the IP-based authentication rules. When phpMyAdmin is used with IPv6 in a proxy server environment, and the proxy server is in the allowed range but the attacking computer is not allowed, this vulnerability can allow the attacking computer to connect despite the IP rules. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6624?
CVE-2016-6624 has a moderate severity as it involves improper validation of IP-based authentication rules.
How do I fix CVE-2016-6624?
To mitigate CVE-2016-6624, upgrade phpMyAdmin to version 4.0.10.17 or later, 4.4.15.8 or later, or 4.6.4.
What versions of phpMyAdmin are affected by CVE-2016-6624?
CVE-2016-6624 affects phpMyAdmin versions from 4.0.0 to 4.0.10.16, 4.4.0 to 4.4.15.7, and 4.6.0 to 4.6.3.
Can CVE-2016-6624 be exploited in a secure network?
Yes, CVE-2016-6624 can be exploited if an attacker has access to the allowed range through a proxy server, regardless of network security.
Is there a workaround for CVE-2016-6624 if I cannot upgrade?
While upgrading is the recommended solution, temporarily restricting access to phpMyAdmin could act as a workaround until an upgrade can be performed.