High severity8.1NVD Advisory· Published Dec 11, 2016· Updated May 6, 2026
CVE-2016-6617
CVE-2016-6617
Description
An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4) are affected.
Affected products
4cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.phpmyadmin.net/security/PMASA-2016-40nvdPatchVendor Advisory
- www.securityfocus.com/bid/95044nvd
- security.gentoo.org/glsa/201701-32nvd
News mentions
0No linked articles in our index yet.