Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

github логотип

GHSA-jjpc-pf2f-wwgg

около 4 лет назад

The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a direct request to wp-content/plugins/portable-phpmyadmin/wp-pma-mod.

EPSS: Средний
github логотип

GHSA-g39j-4qc9-5rh4

около 4 лет назад

phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.

EPSS: Высокий
github логотип

GHSA-rfpg-2fp8-2fph

около 4 лет назад

phpMyAdmin multiple cross-site scripting vulnerabilities

EPSS: Низкий
github логотип

GHSA-xpxp-v33m-5jp9

около 4 лет назад

phpMyAdmin Unsafe Fetching of Javascript Code

EPSS: Низкий
github логотип

GHSA-r3pq-mp8v-cp33

около 4 лет назад

phpMyAdmin Multiple Cross-site Scripting Vulnerabilities in the Database Structure page

EPSS: Низкий
github логотип

GHSA-x962-w72p-mv7q

около 4 лет назад

phpMyAdmin Global variables scope injection vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-cq7h-9hgp-vpjq

около 4 лет назад

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.

EPSS: Низкий
github логотип

GHSA-5gh4-v2ch-pcx4

около 4 лет назад

phpMyAdmin Multiple cross-site scripting (XSS) vulnerabilities

EPSS: Низкий
github логотип

GHSA-vp7p-rxfv-rwm2

около 4 лет назад

phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files.

EPSS: Низкий
github логотип

GHSA-f6c3-pp9c-mrf5

около 4 лет назад

Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-jjpc-pf2f-wwgg

The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a direct request to wp-content/plugins/portable-phpmyadmin/wp-pma-mod.

24%
Средний
около 4 лет назад
github логотип
GHSA-g39j-4qc9-5rh4

phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.

75%
Высокий
около 4 лет назад
github логотип
GHSA-rfpg-2fp8-2fph

phpMyAdmin multiple cross-site scripting vulnerabilities

1%
Низкий
около 4 лет назад
github логотип
GHSA-xpxp-v33m-5jp9

phpMyAdmin Unsafe Fetching of Javascript Code

1%
Низкий
около 4 лет назад
github логотип
GHSA-r3pq-mp8v-cp33

phpMyAdmin Multiple Cross-site Scripting Vulnerabilities in the Database Structure page

1%
Низкий
около 4 лет назад
github логотип
GHSA-x962-w72p-mv7q

phpMyAdmin Global variables scope injection vulnerability

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-cq7h-9hgp-vpjq

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.

1%
Низкий
около 4 лет назад
github логотип
GHSA-5gh4-v2ch-pcx4

phpMyAdmin Multiple cross-site scripting (XSS) vulnerabilities

1%
Низкий
около 4 лет назад
github логотип
GHSA-vp7p-rxfv-rwm2

phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files.

2%
Низкий
около 4 лет назад
github логотип
GHSA-f6c3-pp9c-mrf5

Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться