CVE-2016-5733

medium
Published 2016-07-03 · Modified 2025-04-14
CVSS v3
6.1
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2
4.3
VIR risk
6.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted table name that is mishandled during privilege checking in table_row.phtml, (2) a crafted mysqld log_bin directive that is mishandled in log_selector.phtml, (3) the Transformation implementation, (4) AJAX error handling in js/ajax.js, (5) the Designer implementation, (6) the charts implementation in js/tbl_chart.js, or (7) the zoom-search implementation in rows_zoom.phtml.

Predictions

Exploit likelihood
71%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-5733

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.phpmyadmin.net/security/PMASA-2016-26/

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/d648ade18d6cbb796a93261491c121f078df2d88

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/be3ecbb4cca3fbe20e3b3aa4e049902d18b60865

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/960fd1fd52023047a23d069178bfff7463c2cefc

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/895a131d2eb7e447757a35d5731c7d647823ea8b

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/8716855b309dbe65d7b9a5d681b80579b225b322

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/79661610f6f65443e0ec1e382a7240437f28436c

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/615212a14d7d87712202f37354acf8581987fc5a

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/phpmyadmin/phpmyadmin/commit/4d21b5c077db50c2a54b7f569d20f463cc2651f5

OS impact

OSVersionStatusFixed in
suse suse42.1affected
suse suse13.1affected
suse suse13.2affected
debian debianbookwormfixed4:4.6.3-1
debian debianbullseyefixed4:4.6.3-1
debian debiansidfixed4:4.6.3-1
debian debiantrixiefixed4:4.6.3-1

Package impact

EcosystemPackageVulnerableFixed
php Packagistphpmyadmin/phpmyadmin>=4.0.10.0,<4.0.10.164.0.10.16
php Packagistphpmyadmin/phpmyadmin>=4.4.15.0,<4.4.15.74.4.15.7
php Packagistphpmyadmin/phpmyadmin>=4.6.0,<4.6.34.6.3

Application impact

VendorProductVersionsFixed
phpmyadminphpmyadmin4.0.0
phpmyadminphpmyadmin4.0.1
phpmyadminphpmyadmin4.0.2
phpmyadminphpmyadmin4.0.3
phpmyadminphpmyadmin4.0.4
phpmyadminphpmyadmin4.0.4.1
phpmyadminphpmyadmin4.0.4.2
phpmyadminphpmyadmin4.0.5
phpmyadminphpmyadmin4.0.6
phpmyadminphpmyadmin4.0.7
phpmyadminphpmyadmin4.0.8
phpmyadminphpmyadmin4.0.9
phpmyadminphpmyadmin4.0.10
phpmyadminphpmyadmin4.0.10.1
phpmyadminphpmyadmin4.0.10.2
phpmyadminphpmyadmin4.0.10.3
phpmyadminphpmyadmin4.0.10.4
phpmyadminphpmyadmin4.0.10.5
phpmyadminphpmyadmin4.0.10.6
phpmyadminphpmyadmin4.0.10.7
phpmyadminphpmyadmin4.0.10.8
phpmyadminphpmyadmin4.0.10.9
phpmyadminphpmyadmin4.0.10.10
phpmyadminphpmyadmin4.0.10.11
phpmyadminphpmyadmin4.0.10.12
phpmyadminphpmyadmin4.0.10.13
phpmyadminphpmyadmin4.0.10.14
phpmyadminphpmyadmin4.0.10.15
phpmyadminphpmyadmin4.4.0
phpmyadminphpmyadmin4.4.1
phpmyadminphpmyadmin4.4.1.1
phpmyadminphpmyadmin4.4.2
phpmyadminphpmyadmin4.4.3
phpmyadminphpmyadmin4.4.4
phpmyadminphpmyadmin4.4.5
phpmyadminphpmyadmin4.4.6
phpmyadminphpmyadmin4.4.6.1
phpmyadminphpmyadmin4.4.7
phpmyadminphpmyadmin4.4.8
phpmyadminphpmyadmin4.4.9
phpmyadminphpmyadmin4.4.10
phpmyadminphpmyadmin4.4.11
phpmyadminphpmyadmin4.4.12
phpmyadminphpmyadmin4.4.13
phpmyadminphpmyadmin4.4.13.1
phpmyadminphpmyadmin4.4.14.1
phpmyadminphpmyadmin4.4.15
phpmyadminphpmyadmin4.4.15.1
phpmyadminphpmyadmin4.4.15.2
phpmyadminphpmyadmin4.4.15.3
phpmyadminphpmyadmin4.4.15.4
phpmyadminphpmyadmin4.4.15.5
phpmyadminphpmyadmin4.4.15.6
phpmyadminphpmyadmin4.6.0
phpmyadminphpmyadmin4.6.1
phpmyadminphpmyadmin4.6.2

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.