VulnerabilityModified
CVE-2016-6608
XSS issues were discovered in phpMyAdmin.
MEDIUM 6.1EPSS 1.28%
Does this matter?
Lower severity and a low EPSS score (1.28%). Track it; it rarely justifies an emergency change on its own.
Description
XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.28% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- phpmyadmin/phpmyadmin
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/93258
- https://security.gentoo.org/glsa/201701-32
- https://www.phpmyadmin.net/security/PMASA-2016-31Patch, Vendor Advisory
- http://www.securityfocus.com/bid/93258
- https://security.gentoo.org/glsa/201701-32
- https://www.phpmyadmin.net/security/PMASA-2016-31Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.