Количество 1 093
Количество 1 093

openSUSE-SU-2019:2211-1
Security update for phpMyAdmin

openSUSE-SU-2018:2525-2
Security update for phpMyAdmin

openSUSE-SU-2018:2525-1
Security update for phpMyAdmin

openSUSE-SU-2018:2523-1
Security update for phpMyAdmin

openSUSE-SU-2016:1434-1
Security update for phpMyAdmin

openSUSE-SU-2016:0067-1
Security update for phpMyAdmin

openSUSE-SU-2015:1930-1
Security update for phpMyAdmin
GHSA-xwf2-53mc-r8hx
phpMyAdmin CSRF Vulnerability
GHSA-xrpq-63mp-9vcw
phpMyAdmin HTTP Response Splitting Vulnerability
GHSA-xqw9-ffx7-g998
phpMyAdmin cookie-attribute injection
GHSA-xqqq-qrvp-j2jg
phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.
GHSA-xq8v-3x6g-9vpm
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.
GHSA-xpxp-v33m-5jp9
phpMyAdmin Unsafe Fetching of Javascript Code
GHSA-xhqq-554j-p4x8
phpMyAdmin Directory Traversal Vulnerability
GHSA-xc97-r49q-cxgc
phpMyAdmin Local file inclusion through transformation feature
GHSA-x962-w72p-mv7q
phpMyAdmin Global variables scope injection vulnerability
GHSA-x95j-5m75-mq26
Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.
GHSA-x8fh-8c7v-9r64
PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/darkblue_orange/layout.inc.php; and via the (1) lang[], (2) target[], (3) db[], (4) goto[], (5) table[], and (6) tbl_group[] array arguments to (c) index.php, and the (7) back[] argument to (d) sql.php; and an invalid (8) sort_by parameter to (e) server_databases.php and (9) db parameter to (f) db_printview.php.
GHSA-x7xh-qj32-6gv8
The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme.
GHSA-x5rx-xjw2-pgfp
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.x before 2.8.0.4 allows remote attackers to inject arbitrary web script or HTML via the theme parameter in unknown scripts. NOTE: the lang parameter is already covered by CVE-2006-2031.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | openSUSE-SU-2019:2211-1 Security update for phpMyAdmin | 32% Средний | почти 6 лет назад | |
![]() | openSUSE-SU-2018:2525-2 Security update for phpMyAdmin | 1% Низкий | почти 7 лет назад | |
![]() | openSUSE-SU-2018:2525-1 Security update for phpMyAdmin | 1% Низкий | почти 7 лет назад | |
![]() | openSUSE-SU-2018:2523-1 Security update for phpMyAdmin | 1% Низкий | почти 7 лет назад | |
![]() | openSUSE-SU-2016:1434-1 Security update for phpMyAdmin | 0% Низкий | около 9 лет назад | |
![]() | openSUSE-SU-2016:0067-1 Security update for phpMyAdmin | 0% Низкий | больше 9 лет назад | |
![]() | openSUSE-SU-2015:1930-1 Security update for phpMyAdmin | 1% Низкий | почти 10 лет назад | |
GHSA-xwf2-53mc-r8hx phpMyAdmin CSRF Vulnerability | CVSS3: 8.8 | 0% Низкий | около 3 лет назад | |
GHSA-xrpq-63mp-9vcw phpMyAdmin HTTP Response Splitting Vulnerability | 1% Низкий | больше 3 лет назад | ||
GHSA-xqw9-ffx7-g998 phpMyAdmin cookie-attribute injection | CVSS3: 3.7 | 0% Низкий | около 3 лет назад | |
GHSA-xqqq-qrvp-j2jg phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack. | 2% Низкий | больше 3 лет назад | ||
GHSA-xq8v-3x6g-9vpm PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array. | 9% Низкий | больше 3 лет назад | ||
GHSA-xpxp-v33m-5jp9 phpMyAdmin Unsafe Fetching of Javascript Code | 0% Низкий | около 3 лет назад | ||
GHSA-xhqq-554j-p4x8 phpMyAdmin Directory Traversal Vulnerability | 1% Низкий | около 3 лет назад | ||
GHSA-xc97-r49q-cxgc phpMyAdmin Local file inclusion through transformation feature | CVSS3: 6.5 | 2% Низкий | около 3 лет назад | |
GHSA-x962-w72p-mv7q phpMyAdmin Global variables scope injection vulnerability | CVSS3: 5.4 | 0% Низкий | около 3 лет назад | |
GHSA-x95j-5m75-mq26 Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter. | 0% Низкий | около 3 лет назад | ||
GHSA-x8fh-8c7v-9r64 PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/darkblue_orange/layout.inc.php; and via the (1) lang[], (2) target[], (3) db[], (4) goto[], (5) table[], and (6) tbl_group[] array arguments to (c) index.php, and the (7) back[] argument to (d) sql.php; and an invalid (8) sort_by parameter to (e) server_databases.php and (9) db parameter to (f) db_printview.php. | 11% Средний | больше 3 лет назад | ||
GHSA-x7xh-qj32-6gv8 The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme. | 2% Низкий | больше 3 лет назад | ||
GHSA-x5rx-xjw2-pgfp Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.x before 2.8.0.4 allows remote attackers to inject arbitrary web script or HTML via the theme parameter in unknown scripts. NOTE: the lang parameter is already covered by CVE-2006-2031. | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу