CVE-2016-9859: Input Validation
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9859?
CVE-2016-9859 is rated as a high severity vulnerability due to its potential for causing denial of service attacks on phpMyAdmin.
How do I fix CVE-2016-9859?
To fix CVE-2016-9859, upgrade to phpMyAdmin version 4.6.5 or later, 4.4.15.9 or later, or 4.0.10.18 or later.
Which versions of phpMyAdmin are affected by CVE-2016-9859?
CVE-2016-9859 affects phpMyAdmin versions 4.6.x before 4.6.5, 4.4.x before 4.4.15.9, and 4.0.x before 4.0.10.18.
What attack vector is exploited in CVE-2016-9859?
CVE-2016-9859 can be exploited via crafted request parameter values in the import feature of phpMyAdmin.
Is CVE-2016-9859 a remote vulnerability?
Yes, CVE-2016-9859 is a remote vulnerability that allows an attacker to cause denial of service without needing local access.