Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

ubuntu логотип

CVE-2017-1000016

больше 8 лет назад

A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-1000015

больше 8 лет назад

phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-1000018

больше 8 лет назад

phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-1000013

больше 8 лет назад

phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-6621

около 9 лет назад

The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2016-6621

около 9 лет назад

The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15. ...

CVSS3: 8.6
EPSS: Низкий
ubuntu логотип

CVE-2016-6621

около 9 лет назад

The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2016-9866

около 9 лет назад

An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-9866

около 9 лет назад

An issue was discovered in phpMyAdmin. When the arg_separator is diffe ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-9865

около 9 лет назад

An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2017-1000016

A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000015

phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000018

phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name

CVSS3: 7.5
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000013

phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness

CVSS3: 6.1
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2016-6621

The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.

CVSS3: 8.6
0%
Низкий
около 9 лет назад
debian логотип
CVE-2016-6621

The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15. ...

CVSS3: 8.6
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-6621

The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.

CVSS3: 8.6
0%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-9866

An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
0%
Низкий
около 9 лет назад
debian логотип
CVE-2016-9866

An issue was discovered in phpMyAdmin. When the arg_separator is diffe ...

CVSS3: 9.8
0%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-9865

An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
1%
Низкий
около 9 лет назад

Уязвимостей на страницу


Поделиться