CVE-2016-6621

high
Published 2017-01-31 · Modified 2025-04-21
CVSS v3
8.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS v2
5.0
VIR risk
8.6

Description

The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.

Predictions

Exploit likelihood
91%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-6621

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.phpmyadmin.net/security/PMASA-2016-44/

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4:4.6.6-1
debian debianbullseyefixed4:4.6.6-1
debian debiansidfixed4:4.6.6-1
debian debiantrixiefixed4:4.6.6-1

Package impact

EcosystemPackageVulnerableFixed
php Packagistphpmyadmin/phpmyadmin>=4.6.0,<4.6.64.6.6
php Packagistphpmyadmin/phpmyadmin>=4.4.0,<4.4.15.104.4.15.10
php Packagistphpmyadmin/phpmyadmin<4.0.10.194.0.10.19

Application impact

VendorProductVersionsFixed
phpmyadminphpmyadmin{"endIncluding":"4.0.10.18"}
phpmyadminphpmyadmin4.4.0
phpmyadminphpmyadmin4.4.1
phpmyadminphpmyadmin4.4.1.1
phpmyadminphpmyadmin4.4.2
phpmyadminphpmyadmin4.4.3
phpmyadminphpmyadmin4.4.4
phpmyadminphpmyadmin4.4.5
phpmyadminphpmyadmin4.4.6
phpmyadminphpmyadmin4.4.6.1
phpmyadminphpmyadmin4.4.7
phpmyadminphpmyadmin4.4.8
phpmyadminphpmyadmin4.4.9
phpmyadminphpmyadmin4.4.10
phpmyadminphpmyadmin4.4.11
phpmyadminphpmyadmin4.4.12
phpmyadminphpmyadmin4.4.13
phpmyadminphpmyadmin4.4.13.1
phpmyadminphpmyadmin4.4.14.1
phpmyadminphpmyadmin4.4.15
phpmyadminphpmyadmin4.4.15.1
phpmyadminphpmyadmin4.4.15.2
phpmyadminphpmyadmin4.4.15.3
phpmyadminphpmyadmin4.4.15.4
phpmyadminphpmyadmin4.4.15.5
phpmyadminphpmyadmin4.4.15.6
phpmyadminphpmyadmin4.4.15.8
phpmyadminphpmyadmin4.4.15.9
phpmyadminphpmyadmin4.6.0
phpmyadminphpmyadmin4.6.1
phpmyadminphpmyadmin4.6.2
phpmyadminphpmyadmin4.6.4
phpmyadminphpmyadmin4.6.5

References

CWEs

CWE-918

Verify integrity in audit chain (admin only). AS-IS.