VDB
CVE-2016-6624
CVE-2016-6624
PUBLISHED
An issue was discovered in phpMyAdmin involving improper enforcement of the IP-based authentication rules. When phpMyAdmin is used with IPv6 in a proxy server environment, and the proxy server is in the allowed range but the attacking computer is not allowed, this vulnerability can allow the attacking computer to connect despite the IP rules. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
EPSS 0.42% · 62.2th percentile
Risk Scores
EPSS Score
0.42%
62.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:16.04:LTS | phpmyadmin | 0, 4:4.5.0.2-2, 4:4.5.1-1 |
| Ubuntu:Pro:14.04:LTS | phpmyadmin | 0, 4:4.0.6-1, 4:4.0.8-1 |
Timeline
- Dec 11, 2016 CVE Published
- Jul 1, 2017 CVE Updated
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 17, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 1, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2016-6624 third-party-advisory
- http://www.phpmyadmin.net/security/PMASA-2016-47/ third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2016-6624 third-party-advisory