Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

debian логотип

CVE-2016-2040

почти 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0. ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2016-2039

почти 10 лет назад

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-2039

почти 10 лет назад

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-2038

почти 10 лет назад

phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-2038

почти 10 лет назад

phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x be ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-1927

почти 10 лет назад

The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easier for remote attackers to guess passwords via a brute-force approach.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-1927

почти 10 лет назад

The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x be ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-2040

почти 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) search query, or (4) hostname in a Location header.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2016-2038

почти 10 лет назад

phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2016-2042

почти 10 лет назад

phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2016-2040

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0. ...

CVSS3: 5.4
0%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-2039

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.

CVSS3: 5.3
0%
Низкий
почти 10 лет назад
debian логотип
CVE-2016-2039

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x ...

CVSS3: 5.3
0%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-2038

phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.

CVSS3: 5.3
1%
Низкий
почти 10 лет назад
debian логотип
CVE-2016-2038

phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x be ...

CVSS3: 5.3
1%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-1927

The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easier for remote attackers to guess passwords via a brute-force approach.

CVSS3: 7.5
1%
Низкий
почти 10 лет назад
debian логотип
CVE-2016-1927

The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x be ...

CVSS3: 7.5
1%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-2040

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) search query, or (4) hostname in a Location header.

CVSS3: 5.4
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-2038

phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.

CVSS3: 5.3
1%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-2042

phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.

CVSS3: 5.3
1%
Низкий
почти 10 лет назад

Уязвимостей на страницу


Поделиться