Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

github логотип

GHSA-3754-x86m-fj9m

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

EPSS: Низкий
github логотип

GHSA-c958-4j9x-q7w4

больше 3 лет назад

phpMyAdmin Cross-site Scripting (XSS) in the import dialog

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-wh7g-3gvx-9g4r

больше 3 лет назад

phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.

EPSS: Низкий
github логотип

GHSA-fcqp-fp43-h6gm

больше 3 лет назад

Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-97x5-mp4j-qrgq

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-fc5f-944q-53rg

больше 3 лет назад

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-6wfj-2mw7-p5cg

больше 3 лет назад

phpMyAdmin micro history Implementation XSS Vulnerability

EPSS: Низкий
github логотип

GHSA-pvp5-3q7r-jxp6

больше 3 лет назад

server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.

EPSS: Низкий
github логотип

GHSA-6q2j-8h8q-46mr

больше 3 лет назад

phpMyAdmin vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-cr65-p662-fx5c

больше 3 лет назад

phpMyAdmin vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-3754-x86m-fj9m

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-c958-4j9x-q7w4

phpMyAdmin Cross-site Scripting (XSS) in the import dialog

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-wh7g-3gvx-9g4r

phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-fcqp-fp43-h6gm

Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-97x5-mp4j-qrgq

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fc5f-944q-53rg

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-6wfj-2mw7-p5cg

phpMyAdmin micro history Implementation XSS Vulnerability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-pvp5-3q7r-jxp6

server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6q2j-8h8q-46mr

phpMyAdmin vulnerable to Cross-site Scripting

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-cr65-p662-fx5c

phpMyAdmin vulnerable to Cross-site Scripting

CVSS3: 6.1
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться