Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

github логотип

GHSA-wcmm-28rg-mg3r

около 4 лет назад

phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file

EPSS: Низкий
github логотип

GHSA-x95j-5m75-mq26

около 4 лет назад

Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.

EPSS: Низкий
github логотип

GHSA-wgmf-qh83-2587

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name.

EPSS: Низкий
github логотип

GHSA-xhqq-554j-p4x8

около 4 лет назад

phpMyAdmin Directory Traversal Vulnerability

EPSS: Низкий
github логотип

GHSA-q4mm-89q2-xffg

около 4 лет назад

phpMyAdmin vulnerable to XML external entity (XXE) injection attack

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-2h23-c973-x63q

около 4 лет назад

phpMyAdmin Cross-site Scripting vulnerability

EPSS: Низкий
github логотип

GHSA-756j-8p5m-2p7m

около 4 лет назад

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.

EPSS: Средний
github логотип

GHSA-jfjq-rg72-h4xp

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

EPSS: Низкий
github логотип

GHSA-427m-jx2h-q45m

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-2xg6-qhwr-gp7p

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-wcmm-28rg-mg3r

phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file

2%
Низкий
около 4 лет назад
github логотип
GHSA-x95j-5m75-mq26

Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.

3%
Низкий
около 4 лет назад
github логотип
GHSA-wgmf-qh83-2587

Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xhqq-554j-p4x8

phpMyAdmin Directory Traversal Vulnerability

2%
Низкий
около 4 лет назад
github логотип
GHSA-q4mm-89q2-xffg

phpMyAdmin vulnerable to XML external entity (XXE) injection attack

CVSS3: 6.5
13%
Средний
около 4 лет назад
github логотип
GHSA-2h23-c973-x63q

phpMyAdmin Cross-site Scripting vulnerability

1%
Низкий
около 4 лет назад
github логотип
GHSA-756j-8p5m-2p7m

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.

11%
Средний
около 4 лет назад
github логотип
GHSA-jfjq-rg72-h4xp

Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-427m-jx2h-q45m

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2xg6-qhwr-gp7p

Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться