CVE-2016-6614
Gentoo Linux Security Advisory 201701-32
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Se descubrió un problema en phpMyAdmin que implicaba la funcionalidad de reemplazo del nombre de usuario %u de las funcionalidades SaveDir y UploadDir. Cuando se configura la sustitución de nombre de usuario, se puede utilizar un nombre usuario especialmente manipulado para eludir las restricciones que atraviesan el sistema de archivos. Todas las versiones 4.6.x (anteriores a 4.6.4), versiones 4.4.x (anteriores a 4.4.15.8) y versiones 4.0.x (anteriores a 4.0.10.17) están afectadas.
Multiple vulnerabilities have been found in phpMyAdmin, the worst of which could lead to arbitrary code execution. Versions less than 4.6.5.1 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-08-06 CVE Reserved
- 2016-12-11 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/94366 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2018/07/msg00006.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.phpmyadmin.net/security/PMASA-2016-37 | 2018-07-08 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/201701-32 | 2018-07-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.6.0 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.6.0" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.6.1 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.6.1" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.6.2 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.6.2" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.6.3 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.6.3" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.0 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.0" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.1 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.1" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.2 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.2" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.3 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.3" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.4 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.4" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.4.1 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.4.1" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.4.2 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.4.2" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.5 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.5" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.6 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.6" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.7 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.7" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.8 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.8" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.9 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.9" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.1 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.1" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.2 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.2" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.3 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.3" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.4 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.4" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.5 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.5" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.6 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.6" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.7 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.7" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.8 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.8" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.9 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.9" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.10 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.10" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.11 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.11" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.12 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.12" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.13 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.13" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.14 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.14" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.15 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.15" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.0.10.16 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.0.10.16" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.0 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.0" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.1 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.1" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.1.1 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.1.1" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.2 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.2" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.3 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.3" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.4 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.4" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.5 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.5" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.6 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.6" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.6.1 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.6.1" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.7 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.7" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.8 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.8" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.9 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.9" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.10 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.10" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.11 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.11" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.12 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.12" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.13 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.13" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.13.1 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.13.1" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.14 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.14" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.14.1 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.14.1" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.15 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.15" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.15.1 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.15.1" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.15.2 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.15.2" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.15.3 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.15.3" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.15.4 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.15.4" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.15.5 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.15.5" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.15.6 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.15.6" | - |
Affected
| ||||||
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | 4.4.15.7 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version "4.4.15.7" | - |
Affected
|