{"id":"CVE-2016-6608","details":"XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the \"Remove partitioning\" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.","aliases":["GHSA-jfmj-27fp-qp67"],"modified":"2026-07-08T12:54:18.783358Z","published":"2016-12-11T02:59:12.970Z","related":["openSUSE-SU-2024:10054-1"],"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/93258"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201701-32"},{"type":"FIX","url":"https://www.phpmyadmin.net/security/PMASA-2016-31"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/phpmyadmin/phpmyadmin","events":[{"introduced":"37b38431d167915675fc8ab512470528147e72de"},{"last_affected":"f2db92434b71973a1281dfbaec8837e51e602c77"}],"database_specific":{"cpe":["cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.0:*:*:*:*:*:*:*","cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.0:alpha1:*:*:*:*:*:*","cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.0:rc1:*:*:*:*:*:*","cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.0:rc2:*:*:*:*:*:*","cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.1:*:*:*:*:*:*:*","cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:*:*:*:*:*:*:*","cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.6.0"},{"last_affected":"4.6.0"},{"introduced":"4.6.0-alpha1"},{"last_affected":"4.6.0-alpha1"},{"introduced":"4.6.0-rc1"},{"last_affected":"4.6.0-rc1"},{"introduced":"4.6.0-rc2"},{"last_affected":"4.6.0-rc2"},{"introduced":"4.6.1"},{"last_affected":"4.6.1"},{"introduced":"4.6.2"},{"last_affected":"4.6.2"},{"introduced":"4.6.3"},{"last_affected":"4.6.3"}],"source":"CPE_STRING"}}],"versions":["4.6.0","4.6.0-alpha1","4.6.0-rc1","4.6.0-rc2","4.6.1","4.6.2","4.6.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6608.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}