Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

nvd логотип

CVE-2016-6614

больше 9 лет назад

An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2016-6614

больше 9 лет назад

An issue was discovered in phpMyAdmin involving the %u username replac ...

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2016-6613

больше 9 лет назад

An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-6613

больше 9 лет назад

An issue was discovered in phpMyAdmin. A user can specially craft a sy ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-6612

больше 9 лет назад

An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2016-6612

больше 9 лет назад

An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOC ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2016-6611

больше 9 лет назад

An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2016-6611

больше 9 лет назад

An issue was discovered in phpMyAdmin. A specially crafted database an ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2016-6610

больше 9 лет назад

A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-6610

больше 9 лет назад

A full path disclosure vulnerability was discovered in phpMyAdmin wher ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2016-6614

An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a specially-crafted user name can be used to circumvent restrictions to traverse the file system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 6.8
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6614

An issue was discovered in phpMyAdmin involving the %u username replac ...

CVSS3: 6.8
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-6613

An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 5.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6613

An issue was discovered in phpMyAdmin. A user can specially craft a sy ...

CVSS3: 5.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-6612

An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 6.5
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6612

An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOC ...

CVSS3: 6.5
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-6611

An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 8.1
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6611

An issue was discovered in phpMyAdmin. A specially crafted database an ...

CVSS3: 8.1
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-6610

A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 4.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6610

A full path disclosure vulnerability was discovered in phpMyAdmin wher ...

CVSS3: 4.3
0%
Низкий
больше 9 лет назад

Уязвимостей на страницу


Поделиться