CVE-2016-6633: Code Injection
An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remote code execution attack against certain PHP installations that are running with the dbase extension. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6633?
CVE-2016-6633 has a high severity level as it allows remote code execution on vulnerable PHP installations.
How do I fix CVE-2016-6633?
To fix CVE-2016-6633, you should upgrade to phpMyAdmin versions 4.0.10.17, 4.4.15.8, or 4.6.4.
Which phpMyAdmin versions are affected by CVE-2016-6633?
Affected phpMyAdmin versions include all 4.6.x versions prior to 4.6.4, 4.4.x versions before 4.4.15.8, and 4.0.x versions before 4.0.10.17.
What types of attacks are associated with CVE-2016-6633?
CVE-2016-6633 is associated with remote code execution attacks which can compromise server security.
Is there a reference for CVE-2016-6633?
Yes, references for CVE-2016-6633 can be found in advisories such as PMASA-2016-56.