Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.22017201820192020202120222023202420252026

Недавние уязвимости phpMyAdmin

Количество 1 092

github логотип

GHSA-xpxp-v33m-5jp9

около 3 лет назад

phpMyAdmin Unsafe Fetching of Javascript Code

EPSS: Низкий
github логотип

GHSA-g39j-4qc9-5rh4

около 3 лет назад

phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.

EPSS: Высокий
github логотип

GHSA-r3pq-mp8v-cp33

около 3 лет назад

phpMyAdmin Multiple Cross-site Scripting Vulnerabilities in the Database Structure page

EPSS: Низкий
github логотип

GHSA-x962-w72p-mv7q

около 3 лет назад

phpMyAdmin Global variables scope injection vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-5gh4-v2ch-pcx4

около 3 лет назад

phpMyAdmin Multiple cross-site scripting (XSS) vulnerabilities

EPSS: Низкий
github логотип

GHSA-cq7h-9hgp-vpjq

около 3 лет назад

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.

EPSS: Низкий
github логотип

GHSA-vp7p-rxfv-rwm2

около 3 лет назад

phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files.

EPSS: Низкий
github логотип

GHSA-f6c3-pp9c-mrf5

около 3 лет назад

Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.

EPSS: Низкий
github логотип

GHSA-frxq-rqm9-ppcr

около 3 лет назад

phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to Error.class.php and Error_Handler.class.php.

EPSS: Низкий
github логотип

GHSA-372q-3c59-c2w9

около 3 лет назад

Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an invalid SQL CREATE VIEW statement with a crafted name that triggers an error message.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-xpxp-v33m-5jp9

phpMyAdmin Unsafe Fetching of Javascript Code

0%
Низкий
около 3 лет назад
github логотип
GHSA-g39j-4qc9-5rh4

phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.

88%
Высокий
около 3 лет назад
github логотип
GHSA-r3pq-mp8v-cp33

phpMyAdmin Multiple Cross-site Scripting Vulnerabilities in the Database Structure page

0%
Низкий
около 3 лет назад
github логотип
GHSA-x962-w72p-mv7q

phpMyAdmin Global variables scope injection vulnerability

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-5gh4-v2ch-pcx4

phpMyAdmin Multiple cross-site scripting (XSS) vulnerabilities

0%
Низкий
около 3 лет назад
github логотип
GHSA-cq7h-9hgp-vpjq

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.

0%
Низкий
около 3 лет назад
github логотип
GHSA-vp7p-rxfv-rwm2

phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files.

0%
Низкий
около 3 лет назад
github логотип
GHSA-f6c3-pp9c-mrf5

Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.

0%
Низкий
около 3 лет назад
github логотип
GHSA-frxq-rqm9-ppcr

phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to Error.class.php and Error_Handler.class.php.

0%
Низкий
около 3 лет назад
github логотип
GHSA-372q-3c59-c2w9

Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an invalid SQL CREATE VIEW statement with a crafted name that triggers an error message.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться