phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
GHSA-wcmm-28rg-mg3r
phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file
GHSA-x95j-5m75-mq26
Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.
GHSA-wgmf-qh83-2587
Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name.
GHSA-xhqq-554j-p4x8
phpMyAdmin Directory Traversal Vulnerability
GHSA-q4mm-89q2-xffg
phpMyAdmin vulnerable to XML external entity (XXE) injection attack
GHSA-2h23-c973-x63q
phpMyAdmin Cross-site Scripting vulnerability
GHSA-756j-8p5m-2p7m
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.
GHSA-jfjq-rg72-h4xp
Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
GHSA-427m-jx2h-q45m
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.
GHSA-2xg6-qhwr-gp7p
Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-wcmm-28rg-mg3r phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file | 1% Низкий | больше 3 лет назад | ||
GHSA-x95j-5m75-mq26 Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-wgmf-qh83-2587 Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name. | 1% Низкий | больше 3 лет назад | ||
GHSA-xhqq-554j-p4x8 phpMyAdmin Directory Traversal Vulnerability | 1% Низкий | больше 3 лет назад | ||
GHSA-q4mm-89q2-xffg phpMyAdmin vulnerable to XML external entity (XXE) injection attack | CVSS3: 6.5 | 13% Средний | больше 3 лет назад | |
GHSA-2h23-c973-x63q phpMyAdmin Cross-site Scripting vulnerability | 0% Низкий | больше 3 лет назад | ||
GHSA-756j-8p5m-2p7m libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password. | 17% Средний | больше 3 лет назад | ||
GHSA-jfjq-rg72-h4xp Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-427m-jx2h-q45m Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code. | 1% Низкий | больше 3 лет назад | ||
GHSA-2xg6-qhwr-gp7p Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу