phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
GHSA-j8mx-x32r-5rf4
phpMyAdmin XSS Vulnerability
GHSA-r326-mp8g-6xfc
phpMyAdmin Bypass white-list protection for URL redirection
GHSA-hwj9-6xq5-j7qj
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
GHSA-5vmc-9jj9-45xc
An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
GHSA-c9vh-vmq6-qhgr
An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.
GHSA-qgrq-64g6-mmh6
phpMyAdmin DoS Vulnerability
GHSA-jvxx-8xxf-5495
phpMyAdmin CSRF Vulnerability
GHSA-j2cq-h6v2-f875
phpMyAdmin Cookie attribute injection attack
GHSA-ghr7-5368-f73m
Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name.
GHSA-36hv-fqvj-3wq3
The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-j8mx-x32r-5rf4 phpMyAdmin XSS Vulnerability | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-r326-mp8g-6xfc phpMyAdmin Bypass white-list protection for URL redirection | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-hwj9-6xq5-j7qj An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. | CVSS3: 5.3 | 1% Низкий | почти 4 года назад | |
GHSA-5vmc-9jj9-45xc An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-c9vh-vmq6-qhgr An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-qgrq-64g6-mmh6 phpMyAdmin DoS Vulnerability | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-jvxx-8xxf-5495 phpMyAdmin CSRF Vulnerability | CVSS3: 9.8 | 0% Низкий | почти 4 года назад | |
GHSA-j2cq-h6v2-f875 phpMyAdmin Cookie attribute injection attack | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-ghr7-5368-f73m Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name. | 0% Низкий | почти 4 года назад | ||
GHSA-36hv-fqvj-3wq3 The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark. | 3% Низкий | почти 4 года назад |
Уязвимостей на страницу