CVE-2017-1000016: Input Validation
Published Jul 13, 2017
·Updated
A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.
Affected Software
9 affected componentsFixes available
composer/phpmyadmin/phpmyadmin>=4.6<4.6.6
4.6.6
phpMyAdmin phpMyAdmin=4.6.0
phpMyAdmin phpMyAdmin=4.6.1
phpMyAdmin phpMyAdmin=4.6.2
phpMyAdmin phpMyAdmin=4.6.3
phpMyAdmin phpMyAdmin=4.6.4
phpMyAdmin phpMyAdmin=4.6.5
phpMyAdmin phpMyAdmin=4.6.5.1
phpMyAdmin phpMyAdmin=4.6.5.2
Event History
Jul 13, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·02:25 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-1000016?
The severity of CVE-2017-1000016 is classified as moderate due to the potential for attackers to inject arbitrary values into browser cookies.
2
How do I fix CVE-2017-1000016?
To fix CVE-2017-1000016, upgrade to phpMyAdmin version 4.6.6 or later.
3
Which versions of phpMyAdmin are affected by CVE-2017-1000016?
CVE-2017-1000016 affects phpMyAdmin versions 4.6.0 to 4.6.5.2.
4
What kind of attacks can exploit CVE-2017-1000016?
CVE-2017-1000016 can be exploited by attackers to manipulate browser cookies, potentially leading to session hijacking or data manipulation.
5
Is CVE-2017-1000016 a newly discovered vulnerability?
CVE-2017-1000016 is a re-issue of an earlier vulnerability with an incomplete fix that was originally addressed in PMASA-2016-18.