phpMyAdmin — веб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 095
GHSA-wv8g-fx9j-q2jg
phpMyAdmin cross-site scripting Vulnerability via ENUM value
GHSA-xhqq-554j-p4x8
phpMyAdmin Directory Traversal Vulnerability
GHSA-wcmm-28rg-mg3r
phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file
GHSA-xpxp-v33m-5jp9
phpMyAdmin Unsafe Fetching of Javascript Code
GHSA-xqw9-ffx7-g998
phpMyAdmin cookie-attribute injection
GHSA-36hv-fqvj-3wq3
The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.
GHSA-372q-3c59-c2w9
Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an invalid SQL CREATE VIEW statement with a crafted name that triggers an error message.
GHSA-427m-jx2h-q45m
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.
GHSA-4458-ww2x-8wwm
Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.
GHSA-4gv8-hhx3-rq62
An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-wv8g-fx9j-q2jg phpMyAdmin cross-site scripting Vulnerability via ENUM value | 2% Низкий | больше 4 лет назад | ||
GHSA-xhqq-554j-p4x8 phpMyAdmin Directory Traversal Vulnerability | 2% Низкий | больше 4 лет назад | ||
GHSA-wcmm-28rg-mg3r phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file | 2% Низкий | больше 4 лет назад | ||
GHSA-xpxp-v33m-5jp9 phpMyAdmin Unsafe Fetching of Javascript Code | 1% Низкий | больше 4 лет назад | ||
GHSA-xqw9-ffx7-g998 phpMyAdmin cookie-attribute injection | CVSS3: 3.7 | 2% Низкий | больше 4 лет назад | |
GHSA-36hv-fqvj-3wq3 The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark. | 3% Низкий | больше 4 лет назад | ||
GHSA-372q-3c59-c2w9 Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an invalid SQL CREATE VIEW statement with a crafted name that triggers an error message. | 1% Низкий | больше 4 лет назад | ||
GHSA-427m-jx2h-q45m Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code. | 2% Низкий | больше 4 лет назад | ||
GHSA-4458-ww2x-8wwm Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file. | 1% Низкий | больше 4 лет назад | ||
GHSA-4gv8-hhx3-rq62 An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу