'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2016-5734: phpMyAdmin Authenticated Remote Command Execution Vulnerability
Severity:critical
CVE ID:CVE-2016-5734
| Descripiton:
|
PHPMYADMIN is a set of free, web-based MySQL database management tools developed by PHPMYADMIN. This tool creates and deletes databases, creates, deletes, modifies database tables, performs SQL script commands. There is a security vulnerability in phpMyAdmin, which stems from the program without proper selection of separators to avoid using the preg_replace e modifier. Remote attackers can use this vulnerability to perform any PHP code with a special string. The following versions are affected: PHPMYADMIN 4.0.10.16 before 4.0.x prior to version 4.4.15.7, 4.6.x before 4.6.3. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.