phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
CVE-2005-3299
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin ...
CVE-2005-3300
The register_globals emulation layer in grab_globals.php for phpMyAdmi ...
CVE-2005-3299
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.
CVE-2005-3300
The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme.
CVE-2005-2869
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.
CVE-2005-2869
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin befo ...
CVE-2005-2869
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.
CVE-2005-1392
The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script.
CVE-2005-1392
The SQL install script in phpMyAdmin 2.6.2 is created with world-reada ...
CVE-2005-1392
The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2005-3299 PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin ... | CVSS2: 5 | 9% Низкий | около 20 лет назад | |
CVE-2005-3300 The register_globals emulation layer in grab_globals.php for phpMyAdmi ... | CVSS2: 5 | 2% Низкий | около 20 лет назад | |
CVE-2005-3299 PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array. | CVSS2: 5 | 9% Низкий | около 20 лет назад | |
CVE-2005-3300 The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme. | CVSS2: 5 | 2% Низкий | около 20 лет назад | |
CVE-2005-2869 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php. | CVSS2: 4.3 | 12% Средний | больше 20 лет назад | |
CVE-2005-2869 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin befo ... | CVSS2: 4.3 | 12% Средний | больше 20 лет назад | |
CVE-2005-2869 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php. | CVSS2: 4.3 | 12% Средний | больше 20 лет назад | |
CVE-2005-1392 The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script. | CVSS2: 4.6 | 0% Низкий | больше 20 лет назад | |
CVE-2005-1392 The SQL install script in phpMyAdmin 2.6.2 is created with world-reada ... | CVSS2: 4.6 | 0% Низкий | больше 20 лет назад | |
CVE-2005-1392 The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script. | CVSS2: 4.6 | 0% Низкий | больше 20 лет назад |
Уязвимостей на страницу