Описание
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
Ссылки
- Vendor Advisory
- Third Party Advisory
- ExploitPatchThird Party Advisory
- PatchThird Party Advisory
- Vendor Advisory
- Third Party Advisory
- ExploitPatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 5.0.0 (включая) до 5.2.0 (исключая)
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*
EPSS
Процентиль: 87%
0.03397
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-89
CWE-89
Связанные уязвимости
CVSS3: 9.8
ubuntu
больше 2 лет назад
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
CVSS3: 9.8
debian
больше 2 лет назад
SQL Injection vulnerability in function getTableCreationQuery in Creat ...
CVSS3: 9.8
github
больше 2 лет назад
phpmyadmin contains SQL Injection vulnerability
EPSS
Процентиль: 87%
0.03397
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-89
CWE-89