Количество 1 095
Количество 1 095
GHSA-p6h7-29r2-g88f
phpMyAdmin vulnerable to static code injection
GHSA-p632-5w74-x8xx
phpMyAdmin Cross-site scripting (XSS) vulnerability via pageNumber value
GHSA-mwm8-36c5-j5cf
phpMyAdmin Cross-site scripting (XSS) vulnerability
GHSA-mvfx-p4hj-mppj
Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter.
GHSA-mrq8-9564-r9gh
** DISPUTED ** SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task of the program is to support query execution by authenticated users, and no external attack scenario exists without an auto-login configuration. Thus it is likely that this issue will be REJECTED. However, a closely related CSRF issue has been assigned CVE-2005-4450.
GHSA-mrjr-q5hm-729r
libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
GHSA-mq5q-8qfv-7pqr
PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the path in an error message.
GHSA-mpvm-6q83-9rhg
phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory.
GHSA-mj57-whgp-4577
Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename.
GHSA-mhxj-6vf8-mwv3
phpMyAdmin IPv6 and proxy server IP-based authentication rule circumvention
GHSA-mgpp-4w68-qf76
SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query.
GHSA-mg2j-5mpw-m9xf
libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
GHSA-mfr9-pcm3-6mwc
phpMyAdmin CSRF Vulnerability
GHSA-jvxx-8xxf-5495
phpMyAdmin CSRF Vulnerability
GHSA-jqmr-wqgp-8mh2
phpMyAdmin cross-site scripting Vulnerability in Table or Column Names
GHSA-jfmj-27fp-qp67
phpMyAdmin Cross-site Scripting (XSS)
GHSA-jfjq-rg72-h4xp
Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
GHSA-j99q-43xw-28f9
libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.
GHSA-j8mx-x32r-5rf4
phpMyAdmin XSS Vulnerability
GHSA-j8g5-3786-r7g7
Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row information.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-p6h7-29r2-g88f phpMyAdmin vulnerable to static code injection | 41% Средний | больше 3 лет назад | ||
GHSA-p632-5w74-x8xx phpMyAdmin Cross-site scripting (XSS) vulnerability via pageNumber value | 0% Низкий | больше 3 лет назад | ||
GHSA-mwm8-36c5-j5cf phpMyAdmin Cross-site scripting (XSS) vulnerability | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-mvfx-p4hj-mppj Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter. | 2% Низкий | больше 3 лет назад | ||
GHSA-mrq8-9564-r9gh ** DISPUTED ** SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task of the program is to support query execution by authenticated users, and no external attack scenario exists without an auto-login configuration. Thus it is likely that this issue will be REJECTED. However, a closely related CSRF issue has been assigned CVE-2005-4450. | CVSS3: 6.3 | 2% Низкий | почти 4 года назад | |
GHSA-mrjr-q5hm-729r libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-mq5q-8qfv-7pqr PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the path in an error message. | 0% Низкий | почти 4 года назад | ||
GHSA-mpvm-6q83-9rhg phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory. | 1% Низкий | почти 4 года назад | ||
GHSA-mj57-whgp-4577 Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename. | 0% Низкий | больше 3 лет назад | ||
GHSA-mhxj-6vf8-mwv3 phpMyAdmin IPv6 and proxy server IP-based authentication rule circumvention | CVSS3: 5.9 | 0% Низкий | больше 3 лет назад | |
GHSA-mgpp-4w68-qf76 SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query. | CVSS3: 9.8 | 2% Низкий | больше 3 лет назад | |
GHSA-mg2j-5mpw-m9xf libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-mfr9-pcm3-6mwc phpMyAdmin CSRF Vulnerability | CVSS3: 6.5 | 54% Средний | больше 3 лет назад | |
GHSA-jvxx-8xxf-5495 phpMyAdmin CSRF Vulnerability | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-jqmr-wqgp-8mh2 phpMyAdmin cross-site scripting Vulnerability in Table or Column Names | 0% Низкий | больше 3 лет назад | ||
GHSA-jfmj-27fp-qp67 phpMyAdmin Cross-site Scripting (XSS) | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-jfjq-rg72-h4xp Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-j99q-43xw-28f9 libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function. | 16% Средний | почти 4 года назад | ||
GHSA-j8mx-x32r-5rf4 phpMyAdmin XSS Vulnerability | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-j8g5-3786-r7g7 Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row information. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу