Количество 1 093
Количество 1 093
GHSA-p6h7-29r2-g88f
phpMyAdmin vulnerable to static code injection
GHSA-p632-5w74-x8xx
phpMyAdmin Cross-site scripting (XSS) vulnerability via pageNumber value
GHSA-mwm8-36c5-j5cf
phpMyAdmin Cross-site scripting (XSS) vulnerability
GHSA-mvfx-p4hj-mppj
Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter.
GHSA-mrq8-9564-r9gh
** DISPUTED ** SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task of the program is to support query execution by authenticated users, and no external attack scenario exists without an auto-login configuration. Thus it is likely that this issue will be REJECTED. However, a closely related CSRF issue has been assigned CVE-2005-4450.
GHSA-mrjr-q5hm-729r
libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
GHSA-mq5q-8qfv-7pqr
PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the path in an error message.
GHSA-mpvm-6q83-9rhg
phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory.
GHSA-mj57-whgp-4577
Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename.
GHSA-mhxj-6vf8-mwv3
phpMyAdmin IPv6 and proxy server IP-based authentication rule circumvention
GHSA-mgpp-4w68-qf76
SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query.
GHSA-mg2j-5mpw-m9xf
libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
GHSA-mfr9-pcm3-6mwc
phpMyAdmin CSRF Vulnerability
GHSA-jvxx-8xxf-5495
phpMyAdmin CSRF Vulnerability
GHSA-jqmr-wqgp-8mh2
phpMyAdmin cross-site scripting Vulnerability in Table or Column Names
GHSA-jfmj-27fp-qp67
phpMyAdmin Cross-site Scripting (XSS)
GHSA-jfjq-rg72-h4xp
Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
GHSA-j99q-43xw-28f9
libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.
GHSA-j8mx-x32r-5rf4
phpMyAdmin XSS Vulnerability
GHSA-j8g5-3786-r7g7
Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row information.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-p6h7-29r2-g88f phpMyAdmin vulnerable to static code injection | 22% Средний | около 3 лет назад | ||
GHSA-p632-5w74-x8xx phpMyAdmin Cross-site scripting (XSS) vulnerability via pageNumber value | 0% Низкий | около 3 лет назад | ||
GHSA-mwm8-36c5-j5cf phpMyAdmin Cross-site scripting (XSS) vulnerability | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-mvfx-p4hj-mppj Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter. | 2% Низкий | около 3 лет назад | ||
GHSA-mrq8-9564-r9gh ** DISPUTED ** SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task of the program is to support query execution by authenticated users, and no external attack scenario exists without an auto-login configuration. Thus it is likely that this issue will be REJECTED. However, a closely related CSRF issue has been assigned CVE-2005-4450. | CVSS3: 6.3 | 1% Низкий | больше 3 лет назад | |
GHSA-mrjr-q5hm-729r libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад | |
GHSA-mq5q-8qfv-7pqr PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the path in an error message. | 0% Низкий | больше 3 лет назад | ||
GHSA-mpvm-6q83-9rhg phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory. | 1% Низкий | больше 3 лет назад | ||
GHSA-mj57-whgp-4577 Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename. | 0% Низкий | около 3 лет назад | ||
GHSA-mhxj-6vf8-mwv3 phpMyAdmin IPv6 and proxy server IP-based authentication rule circumvention | CVSS3: 5.9 | 0% Низкий | около 3 лет назад | |
GHSA-mgpp-4w68-qf76 SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query. | CVSS3: 9.8 | 2% Низкий | около 3 лет назад | |
GHSA-mg2j-5mpw-m9xf libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад | |
GHSA-mfr9-pcm3-6mwc phpMyAdmin CSRF Vulnerability | CVSS3: 6.5 | 49% Средний | около 3 лет назад | |
GHSA-jvxx-8xxf-5495 phpMyAdmin CSRF Vulnerability | CVSS3: 9.8 | 0% Низкий | около 3 лет назад | |
GHSA-jqmr-wqgp-8mh2 phpMyAdmin cross-site scripting Vulnerability in Table or Column Names | 0% Низкий | около 3 лет назад | ||
GHSA-jfmj-27fp-qp67 phpMyAdmin Cross-site Scripting (XSS) | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-jfjq-rg72-h4xp Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | 0% Низкий | около 3 лет назад | ||
GHSA-j99q-43xw-28f9 libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function. | 13% Средний | больше 3 лет назад | ||
GHSA-j8mx-x32r-5rf4 phpMyAdmin XSS Vulnerability | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-j8g5-3786-r7g7 Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row information. | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу