Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

nvd логотип

CVE-2016-5739

больше 9 лет назад

The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, which makes it easier for remote attackers to conduct CSRF attacks by reading an authentication token in a Referer header, related to libraries/Header.php.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-5739

больше 9 лет назад

The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16 ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-5734

больше 9 лет назад

phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted string, as demonstrated by the table search-and-replace implementation.

CVSS3: 9.8
EPSS: Высокий
debian логотип

CVE-2016-5734

больше 9 лет назад

phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x be ...

CVSS3: 9.8
EPSS: Высокий
nvd логотип

CVE-2016-5733

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted table name that is mishandled during privilege checking in table_row.phtml, (2) a crafted mysqld log_bin directive that is mishandled in log_selector.phtml, (3) the Transformation implementation, (4) AJAX error handling in js/ajax.js, (5) the Designer implementation, (6) the charts implementation in js/tbl_chart.js, or (7) the zoom-search implementation in rows_zoom.phtml.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-5733

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0. ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-5732

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the partition-range implementation in templates/table/structure/display_partitions.phtml in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via crafted table parameters.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-5732

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the partition-r ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-5731

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in examples/openid.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving an OpenID error message.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-5731

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in examples/openid.php in php ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2016-5739

The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, which makes it easier for remote attackers to conduct CSRF attacks by reading an authentication token in a Referer header, related to libraries/Header.php.

CVSS3: 7.5
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-5739

The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16 ...

CVSS3: 7.5
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-5734

phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted string, as demonstrated by the table search-and-replace implementation.

CVSS3: 9.8
75%
Высокий
больше 9 лет назад
debian логотип
CVE-2016-5734

phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x be ...

CVSS3: 9.8
75%
Высокий
больше 9 лет назад
nvd логотип
CVE-2016-5733

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted table name that is mishandled during privilege checking in table_row.phtml, (2) a crafted mysqld log_bin directive that is mishandled in log_selector.phtml, (3) the Transformation implementation, (4) AJAX error handling in js/ajax.js, (5) the Designer implementation, (6) the charts implementation in js/tbl_chart.js, or (7) the zoom-search implementation in rows_zoom.phtml.

CVSS3: 6.1
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-5733

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0. ...

CVSS3: 6.1
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-5732

Multiple cross-site scripting (XSS) vulnerabilities in the partition-range implementation in templates/table/structure/display_partitions.phtml in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via crafted table parameters.

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-5732

Multiple cross-site scripting (XSS) vulnerabilities in the partition-r ...

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-5731

Cross-site scripting (XSS) vulnerability in examples/openid.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving an OpenID error message.

CVSS3: 6.1
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-5731

Cross-site scripting (XSS) vulnerability in examples/openid.php in php ...

CVSS3: 6.1
0%
Низкий
больше 9 лет назад

Уязвимостей на страницу


Поделиться