GHSA-wpww-hx7x-xfjh
Dashboard / Vulnerabilities / GHSA-wpww-hx7x-xfjh
Summary: phpMyAdmin PHP code injection
Details: An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
References: https://nvd.nist.gov/vuln/detail/CVE-2016-6609, https://github.com/phpmyadmin/composer, https://lists.debian.org/debian-lts-announce/2018/07/msg00006.html, https://security.gentoo.org/glsa/201701-32, https://www.phpmyadmin.net/security/PMASA-2016-32, http://www.securityfocus.com/bid/94112
Affected packages
Package
Name: phpmyadmin/phpmyadmin
Purl: pkg:composer/phpmyadmin/phpmyadmin
Affected ranges
Type: ECOSYSTEM
Events:
