phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
GHSA-r2fq-59w2-3vq4
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the curl wrapper issue.
GHSA-rmmf-5xhh-gg27
phpMyAdmin path disclosure
GHSA-wcjq-hpqg-qhvw
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the json_decode issue.
GHSA-hmmx-wxh4-9w8w
phpMyAdmin XSS Vulnerability
GHSA-r2vw-p77f-vc27
phpMyAdmin Bypass logout timeout
GHSA-r6w3-53hv-rjhw
An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
GHSA-j2wm-vcg8-rf5v
An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
GHSA-r326-mp8g-6xfc
phpMyAdmin Bypass white-list protection for URL redirection
GHSA-pqrf-8j6q-rpq5
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in saved searches feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
GHSA-3hw5-fffc-qrg4
phpMyAdmin Denial of Service (DoS)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-r2fq-59w2-3vq4 An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the curl wrapper issue. | CVSS3: 5.3 | 2% Низкий | около 4 лет назад | |
GHSA-rmmf-5xhh-gg27 phpMyAdmin path disclosure | CVSS3: 5.3 | 3% Низкий | около 4 лет назад | |
GHSA-wcjq-hpqg-qhvw An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the json_decode issue. | CVSS3: 5.3 | 2% Низкий | около 4 лет назад | |
GHSA-hmmx-wxh4-9w8w phpMyAdmin XSS Vulnerability | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-r2vw-p77f-vc27 phpMyAdmin Bypass logout timeout | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-r6w3-53hv-rjhw An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. | CVSS3: 9.8 | 2% Низкий | около 4 лет назад | |
GHSA-j2wm-vcg8-rf5v An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. | CVSS3: 5.3 | 2% Низкий | около 4 лет назад | |
GHSA-r326-mp8g-6xfc phpMyAdmin Bypass white-list protection for URL redirection | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-pqrf-8j6q-rpq5 An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in saved searches feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. | CVSS3: 5.3 | 2% Низкий | около 4 лет назад | |
GHSA-3hw5-fffc-qrg4 phpMyAdmin Denial of Service (DoS) | CVSS3: 5.9 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу