← Back

CVE-2016-6615

nvd nist
Published: Dec 11, 2016Modified: May 6, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

XSS issues were discovered in phpMyAdmin. This affects navigation pane and database/table hiding feature (a specially-crafted database name can be used to trigger an XSS attack); the "Tracking" feature (a specially-crafted query can be used to trigger an XSS attack); and GIS visualization feature. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected.

Affected (33)

1 product
Phpmyadmin
Configuration A
26 vulnerable
Vulnerable SoftwareAffected Versions
Phpmyadmin
Version 4.4.0
Version 4.4.1.1
Version 4.4.10
Version 4.4.11
Version 4.4.12
Version 4.4.13.1
Version 4.4.13
Version 4.4.14.1
Version 4.4.15.1
Version 4.4.15.2
Version 4.4.15.3
Version 4.4.15.4
Version 4.4.15.5
Version 4.4.15.6
Version 4.4.15.7
Version 4.4.15
Version 4.4.1
Version 4.4.2
Version 4.4.3
Version 4.4.4
Version 4.4.5
Version 4.4.6.1
Version 4.4.6
Version 4.4.7
Version 4.4.8
Version 4.4.9
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
Phpmyadmin
Version 4.6.0
Version 4.6.0 alpha1
Version 4.6.0 rc1
Version 4.6.0 rc2
Version 4.6.1
Version 4.6.2
Version 4.6.3

References (8)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.