phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
GHSA-rh74-5835-jpxp
phpMyAdmin vulnerable to Cross-site Scripting
GHSA-wm9c-vcv2-vpqc
phpMyAdmin full path disclosure vulnerability
GHSA-mwm8-36c5-j5cf
phpMyAdmin Cross-site scripting (XSS) vulnerability
GHSA-cr65-p662-fx5c
phpMyAdmin vulnerable to Cross-site Scripting
GHSA-9rmm-8fp4-26hv
phpMyAdmin Denial Of Service (DOS) attack
GHSA-mgpp-4w68-qf76
SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query.
GHSA-g564-g9wm-3q4m
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
GHSA-pw34-qf6c-84fc
phpMyAdmin XSS Vulnerability
GHSA-8m97-xc46-rw9w
phpMyAdmin Unsafe comparison of XSRF/CSRF token
GHSA-hc8v-m2rw-4fc4
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-rh74-5835-jpxp phpMyAdmin vulnerable to Cross-site Scripting | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-wm9c-vcv2-vpqc phpMyAdmin full path disclosure vulnerability | CVSS3: 5.3 | 3% Низкий | около 4 лет назад | |
GHSA-mwm8-36c5-j5cf phpMyAdmin Cross-site scripting (XSS) vulnerability | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-cr65-p662-fx5c phpMyAdmin vulnerable to Cross-site Scripting | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-9rmm-8fp4-26hv phpMyAdmin Denial Of Service (DOS) attack | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
GHSA-mgpp-4w68-qf76 SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query. | CVSS3: 9.8 | 2% Низкий | около 4 лет назад | |
GHSA-g564-g9wm-3q4m phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message. | CVSS3: 5.3 | 2% Низкий | около 4 лет назад | |
GHSA-pw34-qf6c-84fc phpMyAdmin XSS Vulnerability | CVSS3: 5.4 | 2% Низкий | около 4 лет назад | |
GHSA-8m97-xc46-rw9w phpMyAdmin Unsafe comparison of XSRF/CSRF token | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
GHSA-hc8v-m2rw-4fc4 libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value. | CVSS3: 5.3 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу