Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

nvd логотип

CVE-2016-6614

около 9 лет назад

An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2016-6614

около 9 лет назад

An issue was discovered in phpMyAdmin involving the %u username replac ...

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2016-6613

около 9 лет назад

An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-6613

около 9 лет назад

An issue was discovered in phpMyAdmin. A user can specially craft a sy ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-6612

около 9 лет назад

An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2016-6612

около 9 лет назад

An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOC ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2016-6611

около 9 лет назад

An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2016-6611

около 9 лет назад

An issue was discovered in phpMyAdmin. A specially crafted database an ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2016-6610

около 9 лет назад

A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-6610

около 9 лет назад

A full path disclosure vulnerability was discovered in phpMyAdmin wher ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2016-6614

An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 6.8
1%
Низкий
около 9 лет назад
debian логотип
CVE-2016-6614

An issue was discovered in phpMyAdmin involving the %u username replac ...

CVSS3: 6.8
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-6613

An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 5.3
0%
Низкий
около 9 лет назад
debian логотип
CVE-2016-6613

An issue was discovered in phpMyAdmin. A user can specially craft a sy ...

CVSS3: 5.3
0%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-6612

An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 6.5
0%
Низкий
около 9 лет назад
debian логотип
CVE-2016-6612

An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOC ...

CVSS3: 6.5
0%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-6611

An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 8.1
0%
Низкий
около 9 лет назад
debian логотип
CVE-2016-6611

An issue was discovered in phpMyAdmin. A specially crafted database an ...

CVSS3: 8.1
0%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-6610

A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 4.3
0%
Низкий
около 9 лет назад
debian логотип
CVE-2016-6610

A full path disclosure vulnerability was discovered in phpMyAdmin wher ...

CVSS3: 4.3
0%
Низкий
около 9 лет назад

Уязвимостей на страницу


Поделиться