Количество 1 095
Количество 1 095
GHSA-p6h7-29r2-g88f
phpMyAdmin vulnerable to static code injection
GHSA-p632-5w74-x8xx
phpMyAdmin Cross-site scripting (XSS) vulnerability via pageNumber value
GHSA-mwm8-36c5-j5cf
phpMyAdmin Cross-site scripting (XSS) vulnerability
GHSA-mvfx-p4hj-mppj
Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter.
GHSA-mrq8-9564-r9gh
** DISPUTED ** SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task of the program is to support query execution by authenticated users, and no external attack scenario exists without an auto-login configuration. Thus it is likely that this issue will be REJECTED. However, a closely related CSRF issue has been assigned CVE-2005-4450.
GHSA-mrjr-q5hm-729r
libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
GHSA-mq5q-8qfv-7pqr
PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the path in an error message.
GHSA-mpvm-6q83-9rhg
phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory.
GHSA-mj57-whgp-4577
Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename.
GHSA-mhxj-6vf8-mwv3
phpMyAdmin IPv6 and proxy server IP-based authentication rule circumvention
GHSA-mgpp-4w68-qf76
SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query.
GHSA-mg2j-5mpw-m9xf
libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
GHSA-mfr9-pcm3-6mwc
phpMyAdmin CSRF Vulnerability
GHSA-jvxx-8xxf-5495
phpMyAdmin CSRF Vulnerability
GHSA-jqmr-wqgp-8mh2
phpMyAdmin cross-site scripting Vulnerability in Table or Column Names
GHSA-jfmj-27fp-qp67
phpMyAdmin Cross-site Scripting (XSS)
GHSA-jfjq-rg72-h4xp
Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
GHSA-j99q-43xw-28f9
libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.
GHSA-j8mx-x32r-5rf4
phpMyAdmin XSS Vulnerability
GHSA-j8g5-3786-r7g7
Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row information.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-p6h7-29r2-g88f phpMyAdmin vulnerable to static code injection | 34% Средний | почти 4 года назад | ||
GHSA-p632-5w74-x8xx phpMyAdmin Cross-site scripting (XSS) vulnerability via pageNumber value | 0% Низкий | почти 4 года назад | ||
GHSA-mwm8-36c5-j5cf phpMyAdmin Cross-site scripting (XSS) vulnerability | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-mvfx-p4hj-mppj Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter. | 1% Низкий | почти 4 года назад | ||
GHSA-mrq8-9564-r9gh ** DISPUTED ** SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task of the program is to support query execution by authenticated users, and no external attack scenario exists without an auto-login configuration. Thus it is likely that this issue will be REJECTED. However, a closely related CSRF issue has been assigned CVE-2005-4450. | CVSS3: 6.3 | 2% Низкий | почти 4 года назад | |
GHSA-mrjr-q5hm-729r libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. | CVSS3: 5.3 | 0% Низкий | почти 4 года назад | |
GHSA-mq5q-8qfv-7pqr PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the path in an error message. | 0% Низкий | почти 4 года назад | ||
GHSA-mpvm-6q83-9rhg phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory. | 1% Низкий | почти 4 года назад | ||
GHSA-mj57-whgp-4577 Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename. | 0% Низкий | почти 4 года назад | ||
GHSA-mhxj-6vf8-mwv3 phpMyAdmin IPv6 and proxy server IP-based authentication rule circumvention | CVSS3: 5.9 | 0% Низкий | почти 4 года назад | |
GHSA-mgpp-4w68-qf76 SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query. | CVSS3: 9.8 | 2% Низкий | почти 4 года назад | |
GHSA-mg2j-5mpw-m9xf libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. | CVSS3: 5.3 | 0% Низкий | почти 4 года назад | |
GHSA-mfr9-pcm3-6mwc phpMyAdmin CSRF Vulnerability | CVSS3: 6.5 | 55% Средний | почти 4 года назад | |
GHSA-jvxx-8xxf-5495 phpMyAdmin CSRF Vulnerability | CVSS3: 9.8 | 0% Низкий | почти 4 года назад | |
GHSA-jqmr-wqgp-8mh2 phpMyAdmin cross-site scripting Vulnerability in Table or Column Names | 0% Низкий | почти 4 года назад | ||
GHSA-jfmj-27fp-qp67 phpMyAdmin Cross-site Scripting (XSS) | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-jfjq-rg72-h4xp Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-j99q-43xw-28f9 libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function. | 16% Средний | почти 4 года назад | ||
GHSA-j8mx-x32r-5rf4 phpMyAdmin XSS Vulnerability | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-j8g5-3786-r7g7 Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row information. | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу