Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

github логотип

GHSA-fffr-hwf6-2q7v

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Host HTTP header, related to libraries/Config.class.php; (2) crafted JSON data, related to file_echo.php; (3) a crafted SQL query, related to js/functions.js; (4) the initial parameter to libraries/server_privileges.lib.php in the user accounts page; or (5) the it parameter to libraries/controllers/TableSearchController.class.php in the zoom search page.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-w8qg-j9fp-hrjf

больше 3 лет назад

phpMyAdmin Improper Input Validation

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-5pmg-qh2c-7j24

больше 3 лет назад

phpMyAdmin allows remote attackers to spoof content via the url parameter

EPSS: Низкий
github логотип

GHSA-mrjr-q5hm-729r

больше 3 лет назад

libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jqmr-wqgp-8mh2

больше 3 лет назад

phpMyAdmin cross-site scripting Vulnerability in Table or Column Names

EPSS: Низкий
github логотип

GHSA-rpvm-cpgc-m3w7

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database, (2) table, or (3) column name that is improperly handled during rendering of the table browse page; a crafted ENUM value that is improperly handled during rendering of the (4) table print view or (5) zoom search page; or (6) a crafted pma_fontsize cookie that is improperly handled during rendering of the home page.

EPSS: Низкий
github логотип

GHSA-mj57-whgp-4577

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename.

EPSS: Низкий
github логотип

GHSA-v6fh-vg22-r6cm

больше 3 лет назад

phpMyAdmin ReCaptcha bypass

EPSS: Средний
github логотип

GHSA-crhx-xmfj-53jv

больше 3 лет назад

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

EPSS: Низкий
github логотип

GHSA-4458-ww2x-8wwm

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-fffr-hwf6-2q7v

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Host HTTP header, related to libraries/Config.class.php; (2) crafted JSON data, related to file_echo.php; (3) a crafted SQL query, related to js/functions.js; (4) the initial parameter to libraries/server_privileges.lib.php in the user accounts page; or (5) the it parameter to libraries/controllers/TableSearchController.class.php in the zoom search page.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-w8qg-j9fp-hrjf

phpMyAdmin Improper Input Validation

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-5pmg-qh2c-7j24

phpMyAdmin allows remote attackers to spoof content via the url parameter

1%
Низкий
больше 3 лет назад
github логотип
GHSA-mrjr-q5hm-729r

libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-jqmr-wqgp-8mh2

phpMyAdmin cross-site scripting Vulnerability in Table or Column Names

0%
Низкий
больше 3 лет назад
github логотип
GHSA-rpvm-cpgc-m3w7

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database, (2) table, or (3) column name that is improperly handled during rendering of the table browse page; a crafted ENUM value that is improperly handled during rendering of the (4) table print view or (5) zoom search page; or (6) a crafted pma_fontsize cookie that is improperly handled during rendering of the home page.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-mj57-whgp-4577

Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-v6fh-vg22-r6cm

phpMyAdmin ReCaptcha bypass

30%
Средний
больше 3 лет назад
github логотип
GHSA-crhx-xmfj-53jv

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-4458-ww2x-8wwm

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться