Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

ubuntu логотип

CVE-2022-0813

больше 4 лет назад

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-8wf2-3ggj-78q9

больше 4 лет назад

Improper Authentication in phpmyadmin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-vcwc-6mr9-8m7c

больше 4 лет назад

Cross-site Scripting in phpmyadmin

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-23808

больше 4 лет назад

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2022-23808

больше 4 лет назад

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker ca ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-23807

больше 4 лет назад

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-23807

больше 4 лет назад

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-23808

больше 4 лет назад

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2022-23807

больше 4 лет назад

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-22278

больше 5 лет назад

phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2022-0813

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-8wf2-3ggj-78q9

Improper Authentication in phpmyadmin

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-vcwc-6mr9-8m7c

Cross-site Scripting in phpmyadmin

CVSS3: 6.1
8%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-23808

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVSS3: 6.1
8%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-23808

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker ca ...

CVSS3: 6.1
8%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-23807

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-23807

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before ...

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-23808

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVSS3: 6.1
8%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-23807

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-22278

phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.

CVSS3: 8.8
2%
Низкий
больше 5 лет назад

Уязвимостей на страницу


Поделиться