SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-6614

An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features.

MEDIUM 6.8EPSS 2.35%

Does this matter?

Lower severity and a low EPSS score (2.35%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS 3.0
6.8 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS
2.35% probability · 83th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
phpmyadmin/phpmyadmin
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.