Security Advisory

CVE-2016-9849

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2016-12-11 02:00:00
Last updated 2024-08-06 02:59:03
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.