CVE-2016-9858: Input Validation
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in saved searches feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9858?
CVE-2016-9858 is classified as a denial of service vulnerability affecting phpMyAdmin.
How do I fix CVE-2016-9858?
To fix CVE-2016-9858, upgrade to phpMyAdmin version 4.6.5 or later, or 4.4.15.9 or later, or 4.0.10.18 or later.
What versions are affected by CVE-2016-9858?
CVE-2016-9858 affects all phpMyAdmin 4.6.x versions prior to 4.6.5, 4.4.x versions prior to 4.4.15.9, and 4.0.x versions prior to 4.0.10.18.
What type of attack can be initiated through CVE-2016-9858?
CVE-2016-9858 can potentially initiate a denial of service attack via crafted request parameter values.
Is CVE-2016-9858 a remote or local vulnerability?
CVE-2016-9858 is considered a remote vulnerability, allowing attackers to exploit it over the network.