Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.22017201820192020202120222023202420252026

Недавние уязвимости phpMyAdmin

Количество 1 092

nvd логотип

CVE-2012-4345

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Empty link or (3) Drop link for a crafted table name.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-4345

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Database St ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-4345

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Empty link or (3) Drop link for a crafted table name.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-4579

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via a Table Operations (1) TRUNCATE or (2) DROP link for a crafted table name, (3) the Add Trigger popup within a Triggers page that references crafted table names, (4) an invalid trigger-creation attempt for a crafted table name, (5) crafted data in a table, or (6) a crafted tooltip label name during GIS data visualization, a different issue than CVE-2012-4345.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-4219

почти 13 лет назад

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-4219

почти 13 лет назад

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remot ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-4219

почти 13 лет назад

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-1190

около 13 лет назад

Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-1190

около 13 лет назад

Cross-site scripting (XSS) vulnerability in the replication-setup func ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-1190

около 13 лет назад

Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2012-4345

Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Empty link or (3) Drop link for a crafted table name.

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-4345

Multiple cross-site scripting (XSS) vulnerabilities in the Database St ...

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-4345

Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Empty link or (3) Drop link for a crafted table name.

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-4579

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via a Table Operations (1) TRUNCATE or (2) DROP link for a crafted table name, (3) the Add Trigger popup within a Triggers page that references crafted table names, (4) an invalid trigger-creation attempt for a crafted table name, (5) crafted data in a table, or (6) a crafted tooltip label name during GIS data visualization, a different issue than CVE-2012-4345.

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-4219

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.

CVSS2: 5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-4219

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remot ...

CVSS2: 5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-4219

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.

CVSS2: 5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-1190

Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.

CVSS2: 4.3
0%
Низкий
около 13 лет назад
debian логотип
CVE-2012-1190

Cross-site scripting (XSS) vulnerability in the replication-setup func ...

CVSS2: 4.3
0%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2012-1190

Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.

CVSS2: 4.3
0%
Низкий
около 13 лет назад

Уязвимостей на страницу


Поделиться