CVE-2016-6621

HIGH

phpMyAdmin <4.0.10.19, <4.4.15.10, <4.6.6 - SSRF

Title source: llm

Description

The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.

Scores

CVSS v3 8.6
EPSS 0.0039
EPSS Percentile 59.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Classification

CWE
CWE-918
Status draft

Affected Products (37)

phpmyadmin/phpmyadmin < 4.0.10.18
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
phpmyadmin/phpmyadmin
... and 22 more

Timeline

Published Jan 31, 2017
Tracked Since Feb 18, 2026