ubuntu · CVE-2016-6631

Quick triage

Priority: high Published: 2016-12-11 02:59:00 UTC Updated: 2025-08-25 22:08:22 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-6631 high priority: Ubuntu including 1 source packages (phpmyadmin), 8 status rows across 8 suites (artful, bionic, precise, trusty, upstream, xenial, yakkety, zesty): not-affected 4, released 3, ignored 1.

Description:

An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the file generator_plugin.sh. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

cvelogic Threat Intelligence