CVE-2016-6631: OS Command Injection
An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the file generatorplugin.sh. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6631?
CVE-2016-6631 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2016-6631?
To fix CVE-2016-6631, upgrade phpMyAdmin to a version newer than 4.4.15.6.
Which phpMyAdmin versions are affected by CVE-2016-6631?
CVE-2016-6631 affects phpMyAdmin versions from 4.0.0 to 4.4.15.6.
Can CVE-2016-6631 be exploited by unauthenticated users?
Yes, CVE-2016-6631 can be exploited by unauthenticated users under specific server configurations.
What type of attack is associated with CVE-2016-6631?
CVE-2016-6631 is associated with a remote code execution attack.