Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

ubuntu логотип

CVE-2016-6608

около 9 лет назад

XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-5099

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-5099

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4. ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-5098

больше 9 лет назад

Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-5098

больше 9 лет назад

Directory traversal vulnerability in libraries/error_report.lib.php in ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-5097

больше 9 лет назад

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-5097

больше 9 лет назад

phpMyAdmin before 4.6.2 places tokens in query strings and does not ar ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2016-5098

больше 9 лет назад

Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2016-5097

больше 9 лет назад

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2016-5099

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2016-6608

XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.

CVSS3: 6.1
0%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-5099

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-5099

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4. ...

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-5098

Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.

CVSS3: 5.3
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-5098

Directory traversal vulnerability in libraries/error_report.lib.php in ...

CVSS3: 5.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-5097

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.

CVSS3: 5.3
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-5097

phpMyAdmin before 4.6.2 places tokens in query strings and does not ar ...

CVSS3: 5.3
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-5098

Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.

CVSS3: 5.3
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-5097

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.

CVSS3: 5.3
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-5099

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.

CVSS3: 6.1
0%
Низкий
больше 9 лет назад

Уязвимостей на страницу


Поделиться