phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
GHSA-4953-8rw3-w7m5
show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.
GHSA-gqmj-f46x-wqhw
phpMyAdmin Cross-site scripting (XSS) vulnerability in central columns feature
GHSA-v6fp-h79x-9rqc
phpMyAdmin CSRF vulnerability allowing arbitrary SQL execution
GHSA-7rqv-2fvv-3pcq
An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected.
GHSA-rv6m-chvv-wmxg
phpMyAdmin Denial of service (DOS) attack in transformation feature
GHSA-97fm-cg55-639q
An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
GHSA-678w-6p5f-47x3
An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
GHSA-44vv-mm86-7cg6
phpMyAdmin server-side request forgery (SSRF)
GHSA-qf3f-7x69-qfv3
phpMyAdmin DoS Vulnerability
GHSA-grjf-44jw-phc3
XSS issues were discovered in phpMyAdmin. This affects navigation pane and database/table hiding feature (a specially-crafted database name can be used to trigger an XSS attack); the "Tracking" feature (a specially-crafted query can be used to trigger an XSS attack); and GIS visualization feature. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-4953-8rw3-w7m5 show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file. | 0% Низкий | больше 3 лет назад | ||
GHSA-gqmj-f46x-wqhw phpMyAdmin Cross-site scripting (XSS) vulnerability in central columns feature | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-v6fp-h79x-9rqc phpMyAdmin CSRF vulnerability allowing arbitrary SQL execution | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-7rqv-2fvv-3pcq An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-rv6m-chvv-wmxg phpMyAdmin Denial of service (DOS) attack in transformation feature | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-97fm-cg55-639q An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 6.8 | 1% Низкий | больше 3 лет назад | |
GHSA-678w-6p5f-47x3 An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-44vv-mm86-7cg6 phpMyAdmin server-side request forgery (SSRF) | CVSS3: 8.6 | 0% Низкий | больше 3 лет назад | |
GHSA-qf3f-7x69-qfv3 phpMyAdmin DoS Vulnerability | CVSS3: 5.9 | 1% Низкий | больше 3 лет назад | |
GHSA-grjf-44jw-phc3 XSS issues were discovered in phpMyAdmin. This affects navigation pane and database/table hiding feature (a specially-crafted database name can be used to trigger an XSS attack); the "Tracking" feature (a specially-crafted query can be used to trigger an XSS attack); and GIS visualization feature. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу