phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
GHSA-3754-x86m-fj9m
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.
GHSA-c958-4j9x-q7w4
phpMyAdmin Cross-site Scripting (XSS) in the import dialog
GHSA-wh7g-3gvx-9g4r
phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.
GHSA-fcqp-fp43-h6gm
Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.
GHSA-97x5-mp4j-qrgq
Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.
GHSA-fc5f-944q-53rg
phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.
GHSA-6wfj-2mw7-p5cg
phpMyAdmin micro history Implementation XSS Vulnerability
GHSA-pvp5-3q7r-jxp6
server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.
GHSA-6q2j-8h8q-46mr
phpMyAdmin vulnerable to Cross-site Scripting
GHSA-cr65-p662-fx5c
phpMyAdmin vulnerable to Cross-site Scripting
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-3754-x86m-fj9m Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977. | 8% Низкий | больше 3 лет назад | ||
GHSA-c958-4j9x-q7w4 phpMyAdmin Cross-site Scripting (XSS) in the import dialog | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-wh7g-3gvx-9g4r phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php. | 2% Низкий | больше 3 лет назад | ||
GHSA-fcqp-fp43-h6gm Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-97x5-mp4j-qrgq Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-fc5f-944q-53rg phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
GHSA-6wfj-2mw7-p5cg phpMyAdmin micro history Implementation XSS Vulnerability | 0% Низкий | больше 3 лет назад | ||
GHSA-pvp5-3q7r-jxp6 server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request. | 0% Низкий | больше 3 лет назад | ||
GHSA-6q2j-8h8q-46mr phpMyAdmin vulnerable to Cross-site Scripting | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-cr65-p662-fx5c phpMyAdmin vulnerable to Cross-site Scripting | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу