phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
GHSA-r326-mp8g-6xfc
phpMyAdmin Bypass white-list protection for URL redirection
GHSA-3hw5-fffc-qrg4
phpMyAdmin Denial of Service (DoS)
GHSA-j8mx-x32r-5rf4
phpMyAdmin XSS Vulnerability
GHSA-5vmc-9jj9-45xc
An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
GHSA-qgrq-64g6-mmh6
phpMyAdmin DoS Vulnerability
GHSA-c9vh-vmq6-qhgr
An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.
GHSA-jvxx-8xxf-5495
phpMyAdmin CSRF Vulnerability
GHSA-j2cq-h6v2-f875
phpMyAdmin Cookie attribute injection attack
GHSA-ghr7-5368-f73m
Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name.
GHSA-36hv-fqvj-3wq3
The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-r326-mp8g-6xfc phpMyAdmin Bypass white-list protection for URL redirection | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-3hw5-fffc-qrg4 phpMyAdmin Denial of Service (DoS) | CVSS3: 5.9 | 2% Низкий | около 4 лет назад | |
GHSA-j8mx-x32r-5rf4 phpMyAdmin XSS Vulnerability | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-5vmc-9jj9-45xc An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-qgrq-64g6-mmh6 phpMyAdmin DoS Vulnerability | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-c9vh-vmq6-qhgr An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected. | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-jvxx-8xxf-5495 phpMyAdmin CSRF Vulnerability | CVSS3: 9.8 | 1% Низкий | около 4 лет назад | |
GHSA-j2cq-h6v2-f875 phpMyAdmin Cookie attribute injection attack | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-ghr7-5368-f73m Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name. | 2% Низкий | около 4 лет назад | ||
GHSA-36hv-fqvj-3wq3 The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark. | 3% Низкий | около 4 лет назад |
Уязвимостей на страницу