Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"
phpMyAdmin

phpMyAdminвеб-приложение с открытым кодом, написанное на языке PHP и представляющее собой веб-интерфейс для администрирования СУБД MySQL.

Релизный цикл, информация об уязвимостях

Продукт: phpMyAdmin
Вендор: phpmyadmin

График релизов

4.74.84.95.05.15.22017201820192020202120222023202420252026

Недавние уязвимости phpMyAdmin

Количество 1 092

ubuntu логотип

CVE-2008-4096

почти 17 лет назад

libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.

CVSS2: 8.5
EPSS: Средний
nvd логотип

CVE-2008-3457

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2008-3456

почти 17 лет назад

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2008-3457

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin be ...

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2008-3456

почти 17 лет назад

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2008-3456

почти 17 лет назад

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2008-3457

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2008-3197

почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2008-3197

почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2 ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2008-3197

почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2008-4096

libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.

CVSS2: 8.5
13%
Средний
почти 17 лет назад
nvd логотип
CVE-2008-3457

Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.

CVSS2: 2.6
1%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3456

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.

CVSS2: 6.4
2%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-3457

Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin be ...

CVSS2: 2.6
1%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-3456

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from ...

CVSS2: 6.4
2%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-3456

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.

CVSS2: 6.4
2%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-3457

Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.

CVSS2: 2.6
1%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3197

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.

CVSS2: 3.5
0%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-3197

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2 ...

CVSS2: 3.5
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-3197

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.

CVSS2: 3.5
0%
Низкий
почти 17 лет назад

Уязвимостей на страницу


Поделиться