Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.22017201820192020202120222023202420252026

Недавние уязвимости phpMyAdmin

Количество 1 092

nvd логотип

CVE-2014-4954

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLinks function in libraries/structure.lib.php in phpMyAdmin 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted table comment that is improperly handled during construction of a database structure page.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2014-4954

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLi ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2014-4954

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLinks function in libraries/structure.lib.php in phpMyAdmin 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted table comment that is improperly handled during construction of a database structure page.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2014-4987

почти 11 лет назад

server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-4955

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted trigger name that is improperly handled on the database triggers page.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2014-4986

почти 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) table name or (2) column name that is improperly handled during construction of an AJAX confirmation message.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2014-4349

около 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2014-4349

около 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1. ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2014-4348

около 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2014-4348

около 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2. ...

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2014-4954

Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLinks function in libraries/structure.lib.php in phpMyAdmin 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted table comment that is improperly handled during construction of a database structure page.

CVSS2: 3.5
0%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-4954

Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLi ...

CVSS2: 3.5
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2014-4954

Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLinks function in libraries/structure.lib.php in phpMyAdmin 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted table comment that is improperly handled during construction of a database structure page.

CVSS2: 3.5
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2014-4987

server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.

CVSS2: 4
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2014-4955

Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted trigger name that is improperly handled on the database triggers page.

CVSS2: 3.5
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2014-4986

Multiple cross-site scripting (XSS) vulnerabilities in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) table name or (2) column name that is improperly handled during construction of an AJAX confirmation message.

CVSS2: 3.5
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-4349

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.

CVSS2: 3.5
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-4349

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1. ...

CVSS2: 3.5
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-4348

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.

CVSS2: 3.5
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-4348

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2. ...

CVSS2: 3.5
0%
Низкий
около 11 лет назад

Уязвимостей на страницу


Поделиться