CVE-2016-6620

critical
Published 2016-12-11 · Modified 2026-05-06
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object instantiation and autoloading. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-6620

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.phpmyadmin.net/security/PMASA-2016-43

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4:4.6.4+dfsg1-1
debian debianbullseyefixed4:4.6.4+dfsg1-1
debian debiansidfixed4:4.6.4+dfsg1-1
debian debiantrixiefixed4:4.6.4+dfsg1-1

Application impact

VendorProductVersionsFixed
phpmyadminphpmyadmin4.6.0
phpmyadminphpmyadmin4.6.1
phpmyadminphpmyadmin4.6.2
phpmyadminphpmyadmin4.6.3
phpmyadminphpmyadmin4.0.0
phpmyadminphpmyadmin4.0.1
phpmyadminphpmyadmin4.0.2
phpmyadminphpmyadmin4.0.3
phpmyadminphpmyadmin4.0.4
phpmyadminphpmyadmin4.0.4.1
phpmyadminphpmyadmin4.0.4.2
phpmyadminphpmyadmin4.0.5
phpmyadminphpmyadmin4.0.6
phpmyadminphpmyadmin4.0.7
phpmyadminphpmyadmin4.0.8
phpmyadminphpmyadmin4.0.9
phpmyadminphpmyadmin4.0.10
phpmyadminphpmyadmin4.0.10.1
phpmyadminphpmyadmin4.0.10.2
phpmyadminphpmyadmin4.0.10.3
phpmyadminphpmyadmin4.0.10.4
phpmyadminphpmyadmin4.0.10.5
phpmyadminphpmyadmin4.0.10.6
phpmyadminphpmyadmin4.0.10.7
phpmyadminphpmyadmin4.0.10.8
phpmyadminphpmyadmin4.0.10.9
phpmyadminphpmyadmin4.0.10.10
phpmyadminphpmyadmin4.0.10.11
phpmyadminphpmyadmin4.0.10.12
phpmyadminphpmyadmin4.0.10.13
phpmyadminphpmyadmin4.0.10.14
phpmyadminphpmyadmin4.0.10.15
phpmyadminphpmyadmin4.0.10.16
phpmyadminphpmyadmin4.4.0
phpmyadminphpmyadmin4.4.1
phpmyadminphpmyadmin4.4.1.1
phpmyadminphpmyadmin4.4.2
phpmyadminphpmyadmin4.4.3
phpmyadminphpmyadmin4.4.4
phpmyadminphpmyadmin4.4.5
phpmyadminphpmyadmin4.4.6
phpmyadminphpmyadmin4.4.6.1
phpmyadminphpmyadmin4.4.7
phpmyadminphpmyadmin4.4.8
phpmyadminphpmyadmin4.4.9
phpmyadminphpmyadmin4.4.10
phpmyadminphpmyadmin4.4.11
phpmyadminphpmyadmin4.4.12
phpmyadminphpmyadmin4.4.13
phpmyadminphpmyadmin4.4.13.1
phpmyadminphpmyadmin4.4.14
phpmyadminphpmyadmin4.4.14.1
phpmyadminphpmyadmin4.4.15
phpmyadminphpmyadmin4.4.15.1
phpmyadminphpmyadmin4.4.15.2
phpmyadminphpmyadmin4.4.15.3
phpmyadminphpmyadmin4.4.15.4
phpmyadminphpmyadmin4.4.15.5
phpmyadminphpmyadmin4.4.15.6
phpmyadminphpmyadmin4.4.15.7

References

CWEs

CWE-502

Verify integrity in audit chain (admin only). AS-IS.