Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted table name that is mishandled during privilege checking in table_row.phtml, (2) a crafted mysqld log_bin directive that is mishandled in log_selector.phtml, (3) the Transformation implementation, (4) AJAX error handling in js/ajax.js, (5) the Designer implementation, (6) the charts implementation in js/tbl_chart.js, or (7) the zoom-search implementation in rows_zoom.phtml
Published Jul 3, 2016
6.1
MEDIUMCVSS 3.0
EPSS 2.18%
Description
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted table name that is mishandled during privilege checking in table_row.phtml, (2) a crafted mysqld log_bin directive that is mishandled in log_selector.phtml, (3) the Transformation implementation, (4) AJAX error handling in js/ajax.js, (5) the Designer implementation, (6) the charts implementation in js/tbl_chart.js, or (7) the zoom-search implementation in rows_zoom.phtml.
Affected products
No data.
Configuration 1
- 4.0.0
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.0.4.1
- 4.0.4.2
- 4.0.5
- 4.0.6
- 4.0.7
- 4.0.8
- 4.0.9
- 4.0.10
- 4.0.10.1
- 4.0.10.2
- 4.0.10.3
- 4.0.10.4
- 4.0.10.5
- 4.0.10.6
- 4.0.10.7
- 4.0.10.8
- 4.0.10.9
- 4.0.10.10
- 4.0.10.11
- 4.0.10.12
- 4.0.10.13
- 4.0.10.14
- 4.0.10.15
Configuration 2
- 4.4.0
- 4.4.1
- 4.4.1.1
- 4.4.2
- 4.4.3
- 4.4.4
- 4.4.5
- 4.4.6
- 4.4.6.1
- 4.4.7
- 4.4.8
- 4.4.9
- 4.4.10
- 4.4.11
- 4.4.12
- 4.4.13
- 4.4.13.1
- 4.4.14.1
- 4.4.15
- 4.4.15.1
- 4.4.15.2
- 4.4.15.3
- 4.4.15.4
- 4.4.15.5
- 4.4.15.6
Configuration 4
- 4.6.0
- 4.6.0
- 4.6.0
- 4.6.0
- 4.6.1
- 4.6.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.18% (0.02182) | 81.71th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.19% (0.02190) | 80.03th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.91% (0.00911) | 74.20th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.22% (0.00224) | 61.56th | v3 (v2023.03.01) |
| Jun 13, 2024 | 0.22% (0.00224) | 60.81th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.22% (0.00224) | 58.80th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.41% (0.03407) | 84.65th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.41% (0.03407) | 83.10th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.41% (0.03407) | 66.20th | v2 (v2022.01.01) |
References (17)
- http://lists.opensuse.org/opensuse-updates/2016-06/msg00113.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2016-06/msg00114.html vendor-advisoryx_refsource_SUSE
- http://www.debian.org/security/2016/dsa-3627 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/91390 vdb-entryx_refsource_BID
- https://github.com/advisories/GHSA-cr65-p662-fx5c Advisory
- https://github.com/phpmyadmin/phpmyadmin/commit/4d21b5c077db50c2a54b7f569d20f463cc2651f5 x_refsource_CONFIRMPatch
- https://github.com/phpmyadmin/phpmyadmin/commit/615212a14d7d87712202f37354acf8581987fc5a x_refsource_CONFIRMPatch
- https://github.com/phpmyadmin/phpmyadmin/commit/79661610f6f65443e0ec1e382a7240437f28436c x_refsource_CONFIRMPatch
- https://github.com/phpmyadmin/phpmyadmin/commit/8716855b309dbe65d7b9a5d681b80579b225b322 x_refsource_CONFIRMPatch
- https://github.com/phpmyadmin/phpmyadmin/commit/895a131d2eb7e447757a35d5731c7d647823ea8b x_refsource_CONFIRMPatch
- https://github.com/phpmyadmin/phpmyadmin/commit/960fd1fd52023047a23d069178bfff7463c2cefc x_refsource_CONFIRMPatch
- https://github.com/phpmyadmin/phpmyadmin/commit/be3ecbb4cca3fbe20e3b3aa4e049902d18b60865 x_refsource_CONFIRMPatch
- https://github.com/phpmyadmin/phpmyadmin/commit/d648ade18d6cbb796a93261491c121f078df2d88 x_refsource_CONFIRMPatch
- https://nvd.nist.gov/vuln/detail/CVE-2016-5733
- https://security.gentoo.org/glsa/201701-32 vendor-advisoryx_refsource_GENTOO
- https://web.archive.org/web/20200227223017/http://www.securityfocus.com/bid/91390
- https://www.phpmyadmin.net/security/PMASA-2016-26 x_refsource_CONFIRMPatchVendor Advisory
Change history (0)
No recorded changes yet.