CVE-2016-9861: High severity phpmyadmin vulnerability
An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9861?
CVE-2016-9861 is a medium severity vulnerability that allows URL white-list protection bypass in phpMyAdmin.
Which versions are affected by CVE-2016-9861?
CVE-2016-9861 affects phpMyAdmin versions 4.6.x prior to 4.6.5, 4.4.x prior to 4.4.15.9, and 4.0.x prior to 4.0.10.18.
How do I fix CVE-2016-9861?
To fix CVE-2016-9861, upgrade phpMyAdmin to version 4.6.5 or later, 4.4.15.9 or later, or 4.0.10.18 or later.
What type of vulnerability is CVE-2016-9861?
CVE-2016-9861 is a security vulnerability that involves inadequate URL matching leading to unauthorized access.
How can I prevent CVE-2016-9861 in my phpMyAdmin setup?
To prevent CVE-2016-9861, ensure you are running the latest version of phpMyAdmin and regularly check for updates.