Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.220172018201920202021202220232024202520262027

Недавние уязвимости phpMyAdmin

Количество 1 095

nvd логотип

CVE-2012-4579

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via a Table Operations (1) TRUNCATE or (2) DROP link for a crafted table name, (3) the Add Trigger popup within a Triggers page that references crafted table names, (4) an invalid trigger-creation attempt for a crafted table name, (5) crafted data in a table, or (6) a crafted tooltip label name during GIS data visualization, a different issue than CVE-2012-4345.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-4579

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5. ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-4345

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Empty link or (3) Drop link for a crafted table name.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-4345

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Database St ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-4345

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Empty link or (3) Drop link for a crafted table name.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-4579

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via a Table Operations (1) TRUNCATE or (2) DROP link for a crafted table name, (3) the Add Trigger popup within a Triggers page that references crafted table names, (4) an invalid trigger-creation attempt for a crafted table name, (5) crafted data in a table, or (6) a crafted tooltip label name during GIS data visualization, a different issue than CVE-2012-4345.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-4219

больше 13 лет назад

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-4219

больше 13 лет назад

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remot ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-4219

больше 13 лет назад

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-1190

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2012-4579

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via a Table Operations (1) TRUNCATE or (2) DROP link for a crafted table name, (3) the Add Trigger popup within a Triggers page that references crafted table names, (4) an invalid trigger-creation attempt for a crafted table name, (5) crafted data in a table, or (6) a crafted tooltip label name during GIS data visualization, a different issue than CVE-2012-4345.

CVSS2: 3.5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-4579

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5. ...

CVSS2: 3.5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-4345

Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Empty link or (3) Drop link for a crafted table name.

CVSS2: 3.5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-4345

Multiple cross-site scripting (XSS) vulnerabilities in the Database St ...

CVSS2: 3.5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-4345

Multiple cross-site scripting (XSS) vulnerabilities in the Database Structure page in phpMyAdmin 3.4.x before 3.4.11.1 and 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) a crafted table name during table creation, or a (2) Empty link or (3) Drop link for a crafted table name.

CVSS2: 3.5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-4579

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.2.2 allow remote authenticated users to inject arbitrary web script or HTML via a Table Operations (1) TRUNCATE or (2) DROP link for a crafted table name, (3) the Add Trigger popup within a Triggers page that references crafted table names, (4) an invalid trigger-creation attempt for a crafted table name, (5) crafted data in a table, or (6) a crafted tooltip label name during GIS data visualization, a different issue than CVE-2012-4345.

CVSS2: 3.5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-4219

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.

CVSS2: 5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-4219

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remot ...

CVSS2: 5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-4219

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message, related to lack of inclusion of the common.inc.php library file.

CVSS2: 5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-1190

Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.

CVSS2: 4.3
0%
Низкий
почти 14 лет назад

Уязвимостей на страницу


Поделиться