CVE-2017-1000018: Input Validation
Published Jul 13, 2017
·Updated
phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name
Affected Software
6 affected componentsFixes available
composer/phpmyadmin/phpmyadmin>=4.0<4.0.10.19
4.0.10.19
composer/phpmyadmin/phpmyadmin>=4.4<4.4.15.10
4.4.15.10
composer/phpmyadmin/phpmyadmin>=4.6<4.6.6
4.6.6
phpMyAdmin phpMyAdmin>=4.0.0<4.0.10.19
phpMyAdmin phpMyAdmin>=4.4.0<4.4.15.10
phpMyAdmin phpMyAdmin>=4.6.0<4.6.6
Remediation
Patch Available
Event History
Jul 13, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
May 14, 2022
Advisory Published
01:18 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-1000018?
CVE-2017-1000018 is classified as a denial-of-service vulnerability.
2
How do I fix CVE-2017-1000018?
To fix CVE-2017-1000018, upgrade phpMyAdmin to version 4.0.10.19, 4.4.15.10, or 4.6.6 or later.
3
Which versions of phpMyAdmin are affected by CVE-2017-1000018?
CVE-2017-1000018 affects phpMyAdmin versions 4.0.x, 4.4.x, and 4.6.x prior to the specified remedial versions.
4
What type of attack can be executed using CVE-2017-1000018?
CVE-2017-1000018 can be exploited to perform a denial-of-service attack by using a specially crafted table name.
5
What protocols are impacted by CVE-2017-1000018?
CVE-2017-1000018 impacts the replication status feature of phpMyAdmin.