Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

github логотип

GHSA-wv8g-fx9j-q2jg

больше 4 лет назад

phpMyAdmin cross-site scripting Vulnerability via ENUM value

EPSS: Низкий
github логотип

GHSA-xhqq-554j-p4x8

больше 4 лет назад

phpMyAdmin Directory Traversal Vulnerability

EPSS: Низкий
github логотип

GHSA-wcmm-28rg-mg3r

больше 4 лет назад

phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file

EPSS: Низкий
github логотип

GHSA-xpxp-v33m-5jp9

больше 4 лет назад

phpMyAdmin Unsafe Fetching of Javascript Code

EPSS: Низкий
github логотип

GHSA-xqw9-ffx7-g998

больше 4 лет назад

phpMyAdmin cookie-attribute injection

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-36hv-fqvj-3wq3

больше 4 лет назад

The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.

EPSS: Низкий
github логотип

GHSA-372q-3c59-c2w9

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an invalid SQL CREATE VIEW statement with a crafted name that triggers an error message.

EPSS: Низкий
github логотип

GHSA-427m-jx2h-q45m

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-4458-ww2x-8wwm

больше 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

EPSS: Низкий
github логотип

GHSA-4gv8-hhx3-rq62

больше 4 лет назад

An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-wv8g-fx9j-q2jg

phpMyAdmin cross-site scripting Vulnerability via ENUM value

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xhqq-554j-p4x8

phpMyAdmin Directory Traversal Vulnerability

2%
Низкий
больше 4 лет назад
github логотип
GHSA-wcmm-28rg-mg3r

phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xpxp-v33m-5jp9

phpMyAdmin Unsafe Fetching of Javascript Code

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqw9-ffx7-g998

phpMyAdmin cookie-attribute injection

CVSS3: 3.7
2%
Низкий
больше 4 лет назад
github логотип
GHSA-36hv-fqvj-3wq3

The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-372q-3c59-c2w9

Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an invalid SQL CREATE VIEW statement with a crafted name that triggers an error message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-427m-jx2h-q45m

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4458-ww2x-8wwm

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4gv8-hhx3-rq62

An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться