Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.22017201820192020202120222023202420252026

Недавние уязвимости phpMyAdmin

Количество 1 092

debian логотип

CVE-2016-2044

больше 9 лет назад

libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5. ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-2043

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the normalization page.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2016-2043

больше 9 лет назад

Cross-site scripting (XSS) vulnerability in the goToFinish1NF function ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2016-2042

больше 9 лет назад

phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-2042

больше 9 лет назад

phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-2041

больше 9 лет назад

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time differences.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-2041

больше 9 лет назад

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x b ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-2040

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) search query, or (4) hostname in a Location header.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2016-2040

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0. ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2016-2039

больше 9 лет назад

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2016-2044

libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5. ...

CVSS3: 5.3
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2043

Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the normalization page.

CVSS3: 5.4
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2043

Cross-site scripting (XSS) vulnerability in the goToFinish1NF function ...

CVSS3: 5.4
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2042

phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.

CVSS3: 5.3
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2042

phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote ...

CVSS3: 5.3
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2041

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time differences.

CVSS3: 7.5
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2041

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x b ...

CVSS3: 7.5
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2040

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) search query, or (4) hostname in a Location header.

CVSS3: 5.4
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2040

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0. ...

CVSS3: 5.4
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2039

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.

CVSS3: 5.3
0%
Низкий
больше 9 лет назад

Уязвимостей на страницу


Поделиться