An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4) are affected.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "4.6.0"
},
{
"introduced": "0"
},
{
"last_affected": "4.6.1"
},
{
"introduced": "0"
},
{
"last_affected": "4.6.2"
},
{
"introduced": "0"
},
{
"last_affected": "4.6.3"
}
]
}