Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

nvd логотип

CVE-2016-6609

больше 9 лет назад

An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-6609

больше 9 лет назад

An issue was discovered in phpMyAdmin. A specially crafted database na ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-6608

больше 9 лет назад

XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-6608

больше 9 лет назад

XSS issues were discovered in phpMyAdmin. This affects the database pr ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-6607

больше 9 лет назад

XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS editor (certain fields in the graphical GIS editor are not properly escaped and can be used to trigger an XSS attack); Relation view; the following Transformations: Formatted, Imagelink, JPEG: Upload, RegexValidation, JPEG inline, PNG inline, and transformation wrapper; XML export; MediaWiki export; Designer; When the MySQL server is running with a specially-crafted log_bin directive; Database tab; Replication feature; and Database search. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-6607

больше 9 лет назад

XSS issues were discovered in phpMyAdmin. This affects Zoom search (sp ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-6606

больше 9 лет назад

An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has access to a user's browser cookie file to decrypt the username and password. Furthermore, the same initialization vector (IV) is used to hash the username and password stored in the phpMyAdmin cookie. If a user has the same password as their username, an attacker who examines the browser cookie can see that they are the same - but the attacker can not directly decode these values from the cookie as it is still hashed. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2016-6606

больше 9 лет назад

An issue was discovered in cookie encryption in phpMyAdmin. The decryp ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2016-4412

больше 9 лет назад

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2016-4412

больше 9 лет назад

An issue was discovered in phpMyAdmin. A user can be tricked into foll ...

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2016-6609

An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 8.8
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6609

An issue was discovered in phpMyAdmin. A specially crafted database na ...

CVSS3: 8.8
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-6608

XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6608

XSS issues were discovered in phpMyAdmin. This affects the database pr ...

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-6607

XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS editor (certain fields in the graphical GIS editor are not properly escaped and can be used to trigger an XSS attack); Relation view; the following Transformations: Formatted, Imagelink, JPEG: Upload, RegexValidation, JPEG inline, PNG inline, and transformation wrapper; XML export; MediaWiki export; Designer; When the MySQL server is running with a specially-crafted log_bin directive; Database tab; Replication feature; and Database search. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 6.1
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6607

XSS issues were discovered in phpMyAdmin. This affects Zoom search (sp ...

CVSS3: 6.1
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-6606

An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has access to a user's browser cookie file to decrypt the username and password. Furthermore, the same initialization vector (IV) is used to hash the username and password stored in the phpMyAdmin cookie. If a user has the same password as their username, an attacker who examines the browser cookie can see that they are the same - but the attacker can not directly decode these values from the cookie as it is still hashed. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 8.1
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-6606

An issue was discovered in cookie encryption in phpMyAdmin. The decryp ...

CVSS3: 8.1
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-4412

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

CVSS3: 4.4
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-4412

An issue was discovered in phpMyAdmin. A user can be tricked into foll ...

CVSS3: 4.4
0%
Низкий
больше 9 лет назад

Уязвимостей на страницу


Поделиться