Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

suse-cvrf логотип

openSUSE-SU-2019:2211-1

почти 6 лет назад

Security update for phpMyAdmin

EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2018:2525-2

почти 7 лет назад

Security update for phpMyAdmin

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:2525-1

почти 7 лет назад

Security update for phpMyAdmin

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:2523-1

почти 7 лет назад

Security update for phpMyAdmin

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:1434-1

около 9 лет назад

Security update for phpMyAdmin

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:0067-1

больше 9 лет назад

Security update for phpMyAdmin

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2015:1930-1

почти 10 лет назад

Security update for phpMyAdmin

EPSS: Низкий
github логотип

GHSA-xwf2-53mc-r8hx

около 3 лет назад

phpMyAdmin CSRF Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrpq-63mp-9vcw

больше 3 лет назад

phpMyAdmin HTTP Response Splitting Vulnerability

EPSS: Низкий
github логотип

GHSA-xqw9-ffx7-g998

около 3 лет назад

phpMyAdmin cookie-attribute injection

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xqqq-qrvp-j2jg

больше 3 лет назад

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.

EPSS: Низкий
github логотип

GHSA-xq8v-3x6g-9vpm

больше 3 лет назад

PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.

EPSS: Низкий
github логотип

GHSA-xpxp-v33m-5jp9

около 3 лет назад

phpMyAdmin Unsafe Fetching of Javascript Code

EPSS: Низкий
github логотип

GHSA-xhqq-554j-p4x8

около 3 лет назад

phpMyAdmin Directory Traversal Vulnerability

EPSS: Низкий
github логотип

GHSA-xc97-r49q-cxgc

около 3 лет назад

phpMyAdmin Local file inclusion through transformation feature

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-x962-w72p-mv7q

около 3 лет назад

phpMyAdmin Global variables scope injection vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-x95j-5m75-mq26

около 3 лет назад

Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.

EPSS: Низкий
github логотип

GHSA-x8fh-8c7v-9r64

больше 3 лет назад

PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/darkblue_orange/layout.inc.php; and via the (1) lang[], (2) target[], (3) db[], (4) goto[], (5) table[], and (6) tbl_group[] array arguments to (c) index.php, and the (7) back[] argument to (d) sql.php; and an invalid (8) sort_by parameter to (e) server_databases.php and (9) db parameter to (f) db_printview.php.

EPSS: Средний
github логотип

GHSA-x7xh-qj32-6gv8

больше 3 лет назад

The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme.

EPSS: Низкий
github логотип

GHSA-x5rx-xjw2-pgfp

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.x before 2.8.0.4 allows remote attackers to inject arbitrary web script or HTML via the theme parameter in unknown scripts. NOTE: the lang parameter is already covered by CVE-2006-2031.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
openSUSE-SU-2019:2211-1

Security update for phpMyAdmin

32%
Средний
почти 6 лет назад
suse-cvrf логотип
openSUSE-SU-2018:2525-2

Security update for phpMyAdmin

1%
Низкий
почти 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:2525-1

Security update for phpMyAdmin

1%
Низкий
почти 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:2523-1

Security update for phpMyAdmin

1%
Низкий
почти 7 лет назад
suse-cvrf логотип
openSUSE-SU-2016:1434-1

Security update for phpMyAdmin

0%
Низкий
около 9 лет назад
suse-cvrf логотип
openSUSE-SU-2016:0067-1

Security update for phpMyAdmin

0%
Низкий
больше 9 лет назад
suse-cvrf логотип
openSUSE-SU-2015:1930-1

Security update for phpMyAdmin

1%
Низкий
почти 10 лет назад
github логотип
GHSA-xwf2-53mc-r8hx

phpMyAdmin CSRF Vulnerability

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xrpq-63mp-9vcw

phpMyAdmin HTTP Response Splitting Vulnerability

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xqw9-ffx7-g998

phpMyAdmin cookie-attribute injection

CVSS3: 3.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-xqqq-qrvp-j2jg

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xq8v-3x6g-9vpm

PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-xpxp-v33m-5jp9

phpMyAdmin Unsafe Fetching of Javascript Code

0%
Низкий
около 3 лет назад
github логотип
GHSA-xhqq-554j-p4x8

phpMyAdmin Directory Traversal Vulnerability

1%
Низкий
около 3 лет назад
github логотип
GHSA-xc97-r49q-cxgc

phpMyAdmin Local file inclusion through transformation feature

CVSS3: 6.5
2%
Низкий
около 3 лет назад
github логотип
GHSA-x962-w72p-mv7q

phpMyAdmin Global variables scope injection vulnerability

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-x95j-5m75-mq26

Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.

0%
Низкий
около 3 лет назад
github логотип
GHSA-x8fh-8c7v-9r64

PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/darkblue_orange/layout.inc.php; and via the (1) lang[], (2) target[], (3) db[], (4) goto[], (5) table[], and (6) tbl_group[] array arguments to (c) index.php, and the (7) back[] argument to (d) sql.php; and an invalid (8) sort_by parameter to (e) server_databases.php and (9) db parameter to (f) db_printview.php.

11%
Средний
больше 3 лет назад
github логотип
GHSA-x7xh-qj32-6gv8

The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-x5rx-xjw2-pgfp

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.x before 2.8.0.4 allows remote attackers to inject arbitrary web script or HTML via the theme parameter in unknown scripts. NOTE: the lang parameter is already covered by CVE-2006-2031.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу