MEDIUM
An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features
Published Dec 11, 2016
6.8
MEDIUMCVSS 3.0
EPSS 2.35%
Description
An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Affected products
No data.
Configuration 1
OR
- 4.6.0
- 4.6.1
- 4.6.2
- 4.6.3
Configuration 2
OR
- 4.0.0
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.0.4.1
- 4.0.4.2
- 4.0.5
- 4.0.6
- 4.0.7
- 4.0.8
- 4.0.9
- 4.0.10
- 4.0.10.1
- 4.0.10.2
- 4.0.10.3
- 4.0.10.4
- 4.0.10.5
- 4.0.10.6
- 4.0.10.7
- 4.0.10.8
- 4.0.10.9
- 4.0.10.10
- 4.0.10.11
- 4.0.10.12
- 4.0.10.13
- 4.0.10.14
- 4.0.10.15
- 4.0.10.16
Configuration 3
OR
- 4.4.0
- 4.4.1
- 4.4.1.1
- 4.4.2
- 4.4.3
- 4.4.4
- 4.4.5
- 4.4.6
- 4.4.6.1
- 4.4.7
- 4.4.8
- 4.4.9
- 4.4.10
- 4.4.11
- 4.4.12
- 4.4.13
- 4.4.13.1
- 4.4.14
- 4.4.14.1
- 4.4.15
- 4.4.15.1
- 4.4.15.2
- 4.4.15.3
- 4.4.15.4
- 4.4.15.5
- 4.4.15.6
- 4.4.15.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://www.securityfocus.com/bid/94366 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://lists.debian.org/debian-lts-announce/2018/07/msg00006.html mailing-listx_refsource_MLIST
- https://security.gentoo.org/glsa/201701-32 vendor-advisoryx_refsource_GENTOO
- https://www.phpmyadmin.net/security/PMASA-2016-37 x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/94366 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://lists.debian.org/debian-lts-announce/2018/07/msg00006.html | mailing-listx_refsource_MLIST | |
| https://security.gentoo.org/glsa/201701-32 | vendor-advisoryx_refsource_GENTOO | |
| https://www.phpmyadmin.net/security/PMASA-2016-37 | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 11, 2016
Updated Aug 6, 2024
Reserved Aug 6, 2016
Link CVE-2016-6614
CISA Vulnrichment
Updated n/a