CVE Vulnerabilities

CVE-2016-9861

Published: Dec 11, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

Affected Software

NameVendorStart VersionEnd Version
PhpmyadminPhpmyadmin4.4.0 (including)4.4.0 (including)
PhpmyadminPhpmyadmin4.4.1 (including)4.4.1 (including)
PhpmyadminPhpmyadmin4.4.1.1 (including)4.4.1.1 (including)
PhpmyadminPhpmyadmin4.4.2 (including)4.4.2 (including)
PhpmyadminPhpmyadmin4.4.3 (including)4.4.3 (including)
PhpmyadminPhpmyadmin4.4.4 (including)4.4.4 (including)
PhpmyadminPhpmyadmin4.4.5 (including)4.4.5 (including)
PhpmyadminPhpmyadmin4.4.6 (including)4.4.6 (including)
PhpmyadminPhpmyadmin4.4.6.1 (including)4.4.6.1 (including)
PhpmyadminPhpmyadmin4.4.7 (including)4.4.7 (including)
PhpmyadminPhpmyadmin4.4.8 (including)4.4.8 (including)
PhpmyadminPhpmyadmin4.4.9 (including)4.4.9 (including)
PhpmyadminPhpmyadmin4.4.10 (including)4.4.10 (including)
PhpmyadminPhpmyadmin4.4.11 (including)4.4.11 (including)
PhpmyadminPhpmyadmin4.4.12 (including)4.4.12 (including)
PhpmyadminPhpmyadmin4.4.13 (including)4.4.13 (including)
PhpmyadminPhpmyadmin4.4.13.1 (including)4.4.13.1 (including)
PhpmyadminPhpmyadmin4.4.14 (including)4.4.14 (including)
PhpmyadminPhpmyadmin4.4.14.1 (including)4.4.14.1 (including)
PhpmyadminPhpmyadmin4.4.15 (including)4.4.15 (including)
PhpmyadminPhpmyadmin4.4.15.1 (including)4.4.15.1 (including)
PhpmyadminPhpmyadmin4.4.15.2 (including)4.4.15.2 (including)
PhpmyadminPhpmyadmin4.4.15.3 (including)4.4.15.3 (including)
PhpmyadminPhpmyadmin4.4.15.4 (including)4.4.15.4 (including)
PhpmyadminPhpmyadmin4.4.15.5 (including)4.4.15.5 (including)
PhpmyadminPhpmyadmin4.4.15.6 (including)4.4.15.6 (including)
PhpmyadminPhpmyadmin4.4.15.7 (including)4.4.15.7 (including)
PhpmyadminPhpmyadmin4.4.15.8 (including)4.4.15.8 (including)
PhpmyadminUbuntuesm-apps/xenial*
PhpmyadminUbuntuesm-infra-legacy/trusty*
PhpmyadminUbuntuprecise*
PhpmyadminUbuntutrusty*
PhpmyadminUbuntutrusty/esm*
PhpmyadminUbuntuupstream*
PhpmyadminUbuntuxenial*
PhpmyadminUbuntuyakkety*

References