Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

github логотип

GHSA-2vcq-4wwg-6wg7

почти 4 года назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-6x9q-9h2v-cmc6

почти 4 года назад

SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.

EPSS: Низкий
github логотип

GHSA-5pvv-f8h3-gw96

почти 4 года назад

phpMyAdmin Cross-site Scripting In MySQL Table Name

EPSS: Низкий
github логотип

GHSA-fm9c-6g88-w6vp

почти 4 года назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.

EPSS: Низкий
github логотип

GHSA-395f-pvp5-hvp6

почти 4 года назад

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

EPSS: Низкий
github логотип

GHSA-fw5c-3235-cprv

почти 4 года назад

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-pgqx-hcp9-24pq

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the export page (display_export.lib.php) in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allow remote attackers to inject arbitrary web script or HTML via the pma_db_filename_template cookie.

EPSS: Низкий
github логотип

GHSA-xrpq-63mp-9vcw

почти 4 года назад

phpMyAdmin HTTP Response Splitting Vulnerability

EPSS: Низкий
github логотип

GHSA-2c4q-6j77-737f

почти 4 года назад

Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable).

EPSS: Низкий
github логотип

GHSA-x3hp-v67w-2vc2

почти 4 года назад

The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte inside a "</script" sequence.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-2vcq-4wwg-6wg7

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-6x9q-9h2v-cmc6

SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.

3%
Низкий
почти 4 года назад
github логотип
GHSA-5pvv-f8h3-gw96

phpMyAdmin Cross-site Scripting In MySQL Table Name

3%
Низкий
почти 4 года назад
github логотип
GHSA-fm9c-6g88-w6vp

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.

1%
Низкий
почти 4 года назад
github логотип
GHSA-395f-pvp5-hvp6

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

1%
Низкий
почти 4 года назад
github логотип
GHSA-fw5c-3235-cprv

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

CVSS3: 9.8
93%
Критический
почти 4 года назад
github логотип
GHSA-pgqx-hcp9-24pq

Multiple cross-site scripting (XSS) vulnerabilities in the export page (display_export.lib.php) in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allow remote attackers to inject arbitrary web script or HTML via the pma_db_filename_template cookie.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xrpq-63mp-9vcw

phpMyAdmin HTTP Response Splitting Vulnerability

1%
Низкий
почти 4 года назад
github логотип
GHSA-2c4q-6j77-737f

Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable).

1%
Низкий
почти 4 года назад
github логотип
GHSA-x3hp-v67w-2vc2

The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte inside a "</script" sequence.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу


Поделиться