phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
GHSA-wcmm-28rg-mg3r
phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file
GHSA-wgmf-qh83-2587
Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name.
GHSA-x95j-5m75-mq26
Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.
GHSA-xhqq-554j-p4x8
phpMyAdmin Directory Traversal Vulnerability
GHSA-q4mm-89q2-xffg
phpMyAdmin vulnerable to XML external entity (XXE) injection attack
GHSA-2h23-c973-x63q
phpMyAdmin Cross-site Scripting vulnerability
GHSA-756j-8p5m-2p7m
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.
GHSA-jfjq-rg72-h4xp
Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
GHSA-427m-jx2h-q45m
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.
GHSA-2xg6-qhwr-gp7p
Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-wcmm-28rg-mg3r phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file | 1% Низкий | почти 4 года назад | ||
GHSA-wgmf-qh83-2587 Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name. | 1% Низкий | почти 4 года назад | ||
GHSA-x95j-5m75-mq26 Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-xhqq-554j-p4x8 phpMyAdmin Directory Traversal Vulnerability | 1% Низкий | почти 4 года назад | ||
GHSA-q4mm-89q2-xffg phpMyAdmin vulnerable to XML external entity (XXE) injection attack | CVSS3: 6.5 | 12% Средний | почти 4 года назад | |
GHSA-2h23-c973-x63q phpMyAdmin Cross-site Scripting vulnerability | 0% Низкий | почти 4 года назад | ||
GHSA-756j-8p5m-2p7m libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password. | 15% Средний | почти 4 года назад | ||
GHSA-jfjq-rg72-h4xp Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-427m-jx2h-q45m Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code. | 1% Низкий | почти 4 года назад | ||
GHSA-2xg6-qhwr-gp7p Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name. | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу