phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
GHSA-567r-vqj7-5cw7
phpMyAdmin Authentication Bypass
GHSA-gv8h-mg99-wgj9
An issue was discovered in phpMyAdmin. An attacker could redirect a user to a malicious web page. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
GHSA-phhm-63xx-v9rr
phpMyAdmin Reflected File Download attack
GHSA-4gv8-hhx3-rq62
An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
GHSA-p849-vf5f-f3x7
phpMyAdmin Remote code execution vulnerability when PHP is running with dbase extension
GHSA-5r36-wxjq-vcfh
An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the file generator_plugin.sh. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
GHSA-426q-975p-w5cr
phpMyAdmin Denial of service (DOS) attack with dbase extension
GHSA-8w5f-7346-5p5m
An issue was discovered in phpMyAdmin. An authenticated user can trigger a denial-of-service (DoS) attack by entering a very long password at the change password dialog. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
GHSA-qc2g-2jgq-733p
An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
GHSA-9xhq-pm7v-693p
phpMyAdmin Cryptographic Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-567r-vqj7-5cw7 phpMyAdmin Authentication Bypass | CVSS3: 9.8 | 3% Низкий | около 4 лет назад | |
GHSA-gv8h-mg99-wgj9 An issue was discovered in phpMyAdmin. An attacker could redirect a user to a malicious web page. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-phhm-63xx-v9rr phpMyAdmin Reflected File Download attack | CVSS3: 6.3 | 1% Низкий | около 4 лет назад | |
GHSA-4gv8-hhx3-rq62 An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-p849-vf5f-f3x7 phpMyAdmin Remote code execution vulnerability when PHP is running with dbase extension | CVSS3: 8.1 | 4% Низкий | около 4 лет назад | |
GHSA-5r36-wxjq-vcfh An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the file generator_plugin.sh. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 7.5 | 5% Низкий | около 4 лет назад | |
GHSA-426q-975p-w5cr phpMyAdmin Denial of service (DOS) attack with dbase extension | CVSS3: 5.9 | 2% Низкий | около 4 лет назад | |
GHSA-8w5f-7346-5p5m An issue was discovered in phpMyAdmin. An authenticated user can trigger a denial-of-service (DoS) attack by entering a very long password at the change password dialog. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 6.5 | 2% Низкий | около 4 лет назад | |
GHSA-qc2g-2jgq-733p An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-9xhq-pm7v-693p phpMyAdmin Cryptographic Vulnerability | CVSS3: 5.3 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу