An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/94366 | Third Party Advisory VDB Entry |
https://lists.debian.org/debian-lts-announce/2018/07/msg00006.html | |
https://security.gentoo.org/glsa/201701-32 | |
https://www.phpmyadmin.net/security/PMASA-2016-37 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/94366 | Third Party Advisory VDB Entry |
https://lists.debian.org/debian-lts-announce/2018/07/msg00006.html | |
https://security.gentoo.org/glsa/201701-32 | |
https://www.phpmyadmin.net/security/PMASA-2016-37 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 02:56
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/94366 - Third Party Advisory, VDB Entry | |
References | () https://lists.debian.org/debian-lts-announce/2018/07/msg00006.html - | |
References | () https://security.gentoo.org/glsa/201701-32 - | |
References | () https://www.phpmyadmin.net/security/PMASA-2016-37 - Patch, Vendor Advisory |
Information
Published : 2016-12-11 02:59
Updated : 2024-11-21 02:56
NVD link : CVE-2016-6614
Mitre link : CVE-2016-6614
CVE.ORG link : CVE-2016-6614
JSON object : View
Products Affected
phpmyadmin
- phpmyadmin
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')