phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
GHSA-4953-8rw3-w7m5
show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.
GHSA-gqmj-f46x-wqhw
phpMyAdmin Cross-site scripting (XSS) vulnerability in central columns feature
GHSA-v6fp-h79x-9rqc
phpMyAdmin CSRF vulnerability allowing arbitrary SQL execution
GHSA-rv6m-chvv-wmxg
phpMyAdmin Denial of service (DOS) attack in transformation feature
GHSA-44vv-mm86-7cg6
phpMyAdmin server-side request forgery (SSRF)
GHSA-wpww-hx7x-xfjh
phpMyAdmin PHP code injection
GHSA-97fm-cg55-639q
An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
GHSA-qf3f-7x69-qfv3
phpMyAdmin DoS Vulnerability
GHSA-7rqv-2fvv-3pcq
An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected.
GHSA-678w-6p5f-47x3
An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-4953-8rw3-w7m5 show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file. | 0% Низкий | почти 4 года назад | ||
GHSA-gqmj-f46x-wqhw phpMyAdmin Cross-site scripting (XSS) vulnerability in central columns feature | CVSS3: 5.4 | 0% Низкий | почти 4 года назад | |
GHSA-v6fp-h79x-9rqc phpMyAdmin CSRF vulnerability allowing arbitrary SQL execution | CVSS3: 8.8 | 1% Низкий | почти 4 года назад | |
GHSA-rv6m-chvv-wmxg phpMyAdmin Denial of service (DOS) attack in transformation feature | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
GHSA-44vv-mm86-7cg6 phpMyAdmin server-side request forgery (SSRF) | CVSS3: 8.6 | 0% Низкий | почти 4 года назад | |
GHSA-wpww-hx7x-xfjh phpMyAdmin PHP code injection | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
GHSA-97fm-cg55-639q An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 6.8 | 1% Низкий | почти 4 года назад | |
GHSA-qf3f-7x69-qfv3 phpMyAdmin DoS Vulnerability | CVSS3: 5.9 | 1% Низкий | почти 4 года назад | |
GHSA-7rqv-2fvv-3pcq An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-678w-6p5f-47x3 An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 8.8 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу