Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10803

Опубликовано: 22 мар. 2020
Источник: nvd
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.9.5 (исключая)
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.0.2 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
Конфигурация 4

Одно из

cpe:2.3:a:opensuse:backports_sle:15.0:-:*:*:*:*:*:*
cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
Конфигурация 5

Одновременно

cpe:2.3:a:suse:package_hub:-:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise:12.0:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.04306
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 5 лет назад

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.

CVSS3: 5.4
debian
около 5 лет назад

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection v ...

CVSS3: 5.4
github
около 3 лет назад

phpMyAdmin SQL injection vulnerability

suse-cvrf
около 5 лет назад

Security update for phpMyAdmin

suse-cvrf
больше 4 лет назад

Security update for phpMyAdmin

EPSS

Процентиль: 88%
0.04306
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79