CVE-2016-9864: SQL Injection
An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9864?
CVE-2016-9864 has a medium severity rating due to the potential for unauthorized access to configuration storage database tables.
How do I fix CVE-2016-9864?
To fix CVE-2016-9864, it is recommended to upgrade phpMyAdmin to version 4.6.5 or later.
What versions of phpMyAdmin are affected by CVE-2016-9864?
CVE-2016-9864 affects phpMyAdmin versions 4.0.0 through 4.6.4.
Can CVE-2016-9864 be exploited remotely?
Yes, CVE-2016-9864 can be exploited remotely through crafted SQL statements.
What are the potential impacts of CVE-2016-9864?
The impacts of CVE-2016-9864 include unauthorized read and write access to the configuration storage database.