SB2016101814 - Cross-site scripting in phpmyadmin (Alpine package)



SB2016101814 - Cross-site scripting in phpmyadmin (Alpine package)

Published: October 18, 2016

Security Bulletin ID SB2016101814
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cross-site scripting (CVE-ID: CVE-2016-6608)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.


Remediation

Install update from vendor's website.