phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
GHSA-hwj9-6xq5-j7qj
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
GHSA-3hw5-fffc-qrg4
phpMyAdmin Denial of Service (DoS)
GHSA-j8mx-x32r-5rf4
phpMyAdmin XSS Vulnerability
GHSA-c9vh-vmq6-qhgr
An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.
GHSA-qgrq-64g6-mmh6
phpMyAdmin DoS Vulnerability
GHSA-5vmc-9jj9-45xc
An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
GHSA-jvxx-8xxf-5495
phpMyAdmin CSRF Vulnerability
GHSA-j2cq-h6v2-f875
phpMyAdmin Cookie attribute injection attack
GHSA-ghr7-5368-f73m
Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name.
GHSA-36hv-fqvj-3wq3
The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-hwj9-6xq5-j7qj An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
GHSA-3hw5-fffc-qrg4 phpMyAdmin Denial of Service (DoS) | CVSS3: 5.9 | 1% Низкий | больше 3 лет назад | |
GHSA-j8mx-x32r-5rf4 phpMyAdmin XSS Vulnerability | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-c9vh-vmq6-qhgr An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-qgrq-64g6-mmh6 phpMyAdmin DoS Vulnerability | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-5vmc-9jj9-45xc An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-jvxx-8xxf-5495 phpMyAdmin CSRF Vulnerability | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-j2cq-h6v2-f875 phpMyAdmin Cookie attribute injection attack | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-ghr7-5368-f73m Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name. | 0% Низкий | больше 3 лет назад | ||
GHSA-36hv-fqvj-3wq3 The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark. | 3% Низкий | больше 3 лет назад |
Уязвимостей на страницу