VDB

CVE-2016-6624

CVE-2016-6624 PUBLISHED CVSS 5.900000095367432 MEDIUM

An issue was discovered in phpMyAdmin involving improper enforcement of the IP-based authentication rules. When phpMyAdmin is used with IPv6 in a proxy server environment, and the proxy server is in the allowed range but the attacking computer is not allowed, this vulnerability can allow the attacking computer to connect despite the IP rules. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

EPSS 2.03% · 80.1th percentile

Risk Scores

CVSS 3.0
5.900000095367432
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
2.03%
80.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSphpmyadmin0, 4:4.5.0.2-2, 4:4.5.1-1
Ubuntu:Pro:14.04:LTSphpmyadmin0, 4:4.0.6-1, 4:4.0.8-1

Timeline

  • Dec 11, 2016 CVE Published
  • Jul 1, 2017 CVE Updated
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 21, 2022 EPSS Score
  • Jul 13, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Oct 28, 2022 EPSS Score
  • Dec 20, 2022 EPSS Score
  • Feb 11, 2023 EPSS Score
  • Apr 5, 2023 EPSS Score
  • May 28, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›