CVE-2016-6631
11.12.2016, 02:59
An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the file generator_plugin.sh. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Vendor | Product | Version |
---|---|---|
phpmyadmin | phpmyadmin | 4.4.0 |
phpmyadmin | phpmyadmin | 4.4.1 |
phpmyadmin | phpmyadmin | 4.4.1.1 |
phpmyadmin | phpmyadmin | 4.4.2 |
phpmyadmin | phpmyadmin | 4.4.3 |
phpmyadmin | phpmyadmin | 4.4.4 |
phpmyadmin | phpmyadmin | 4.4.5 |
phpmyadmin | phpmyadmin | 4.4.6 |
phpmyadmin | phpmyadmin | 4.4.6.1 |
phpmyadmin | phpmyadmin | 4.4.7 |
phpmyadmin | phpmyadmin | 4.4.8 |
phpmyadmin | phpmyadmin | 4.4.9 |
phpmyadmin | phpmyadmin | 4.4.10 |
phpmyadmin | phpmyadmin | 4.4.11 |
phpmyadmin | phpmyadmin | 4.4.12 |
phpmyadmin | phpmyadmin | 4.4.13 |
phpmyadmin | phpmyadmin | 4.4.13.1 |
phpmyadmin | phpmyadmin | 4.4.14 |
phpmyadmin | phpmyadmin | 4.4.14.1 |
phpmyadmin | phpmyadmin | 4.4.15 |
phpmyadmin | phpmyadmin | 4.4.15.1 |
phpmyadmin | phpmyadmin | 4.4.15.2 |
phpmyadmin | phpmyadmin | 4.4.15.3 |
phpmyadmin | phpmyadmin | 4.4.15.4 |
phpmyadmin | phpmyadmin | 4.4.15.5 |
phpmyadmin | phpmyadmin | 4.4.15.6 |
phpmyadmin | phpmyadmin | 4.4.15.7 |
phpmyadmin | phpmyadmin | 4.6.0 |
phpmyadmin | phpmyadmin | 4.6.1 |
phpmyadmin | phpmyadmin | 4.6.2 |
phpmyadmin | phpmyadmin | 4.6.3 |
phpmyadmin | phpmyadmin | 4.0.0 |
phpmyadmin | phpmyadmin | 4.0.1 |
phpmyadmin | phpmyadmin | 4.0.2 |
phpmyadmin | phpmyadmin | 4.0.3 |
phpmyadmin | phpmyadmin | 4.0.4 |
phpmyadmin | phpmyadmin | 4.0.4.1 |
phpmyadmin | phpmyadmin | 4.0.4.2 |
phpmyadmin | phpmyadmin | 4.0.5 |
phpmyadmin | phpmyadmin | 4.0.6 |
phpmyadmin | phpmyadmin | 4.0.7 |
phpmyadmin | phpmyadmin | 4.0.8 |
phpmyadmin | phpmyadmin | 4.0.9 |
phpmyadmin | phpmyadmin | 4.0.10 |
phpmyadmin | phpmyadmin | 4.0.10.1 |
phpmyadmin | phpmyadmin | 4.0.10.2 |
phpmyadmin | phpmyadmin | 4.0.10.3 |
phpmyadmin | phpmyadmin | 4.0.10.4 |
phpmyadmin | phpmyadmin | 4.0.10.5 |
phpmyadmin | phpmyadmin | 4.0.10.6 |
phpmyadmin | phpmyadmin | 4.0.10.7 |
phpmyadmin | phpmyadmin | 4.0.10.8 |
phpmyadmin | phpmyadmin | 4.0.10.9 |
phpmyadmin | phpmyadmin | 4.0.10.10 |
phpmyadmin | phpmyadmin | 4.0.10.11 |
phpmyadmin | phpmyadmin | 4.0.10.12 |
phpmyadmin | phpmyadmin | 4.0.10.13 |
phpmyadmin | phpmyadmin | 4.0.10.14 |
phpmyadmin | phpmyadmin | 4.0.10.15 |
phpmyadmin | phpmyadmin | 4.0.10.16 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References