phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
GHSA-g89x-ccw9-3vqf
phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables.
GHSA-qqgf-6922-rxxc
Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.
GHSA-q8p5-hgjr-4chh
phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.
GHSA-9xhj-74j8-9gxq
phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.
GHSA-pfw8-43jj-c4g3
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.
GHSA-f766-fjw3-vvfv
Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.
BDU:2022-01640
Уязвимость веб-интерфейса веб-приложения для администрирования cистем управления базами данных phpMyAdmin, позволяющая нарушителю получить доступ к конфиденциальной информации
GHSA-vx8q-j7h9-vf6q
Exposure of Sensitive Information to an Unauthorized Actor in PhpMyAdmin
CVE-2022-0813
PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.
CVE-2022-0813
PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-g89x-ccw9-3vqf phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables. | 3% Низкий | почти 4 года назад | ||
GHSA-qqgf-6922-rxxc Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name. | 14% Средний | почти 4 года назад | ||
GHSA-q8p5-hgjr-4chh phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters. | 5% Низкий | почти 4 года назад | ||
GHSA-9xhj-74j8-9gxq phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-pfw8-43jj-c4g3 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser. | 1% Низкий | почти 4 года назад | ||
GHSA-f766-fjw3-vvfv Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter. | 13% Средний | почти 4 года назад | ||
BDU:2022-01640 Уязвимость веб-интерфейса веб-приложения для администрирования cистем управления базами данных phpMyAdmin, позволяющая нарушителю получить доступ к конфиденциальной информации | CVSS3: 5.3 | 0% Низкий | почти 4 года назад | |
GHSA-vx8q-j7h9-vf6q Exposure of Sensitive Information to an Unauthorized Actor in PhpMyAdmin | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
CVE-2022-0813 PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section. | CVSS3: 5.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-0813 PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially ... | CVSS3: 5.3 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу