Количество 1 093
Количество 1 093
GHSA-f6c3-pp9c-mrf5
Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.
GHSA-f47h-66wf-9744
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.
GHSA-cx7j-6x8v-hjf9
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.
GHSA-crhx-xmfj-53jv
libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
GHSA-cr65-p662-fx5c
phpMyAdmin vulnerable to Cross-site Scripting
GHSA-cr49-5764-fxg4
phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers.
GHSA-cq7h-9hgp-vpjq
phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.
GHSA-cq55-4q38-jxr8
An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object instantiation and autoloading. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
GHSA-cj7j-6rg9-9523
Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.
GHSA-c9vh-vmq6-qhgr
An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.
GHSA-c958-4j9x-q7w4
phpMyAdmin Cross-site Scripting (XSS) in the import dialog
GHSA-c8wj-q36q-3wg4
phpMyAdmin Arbitrary file read vulnerability
GHSA-c5vr-rrqf-4hf2
Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) table sections.
GHSA-c2xg-74vm-x8g2
phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files.
GHSA-9xhq-pm7v-693p
phpMyAdmin Cryptographic Vulnerability
GHSA-9xhj-74j8-9gxq
phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.
GHSA-9rmm-8fp4-26hv
phpMyAdmin Denial Of Service (DOS) attack
GHSA-9qwv-267r-c7fq
libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-9j9h-cpgc-8356
phpMyAdmin vulnerable to Cross-site Scripting
GHSA-9hrc-rwrq-v6mh
phpMyAdmin DoS Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-f6c3-pp9c-mrf5 Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link. | 0% Низкий | около 3 лет назад | ||
GHSA-f47h-66wf-9744 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php. | 13% Средний | больше 3 лет назад | ||
GHSA-cx7j-6x8v-hjf9 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function. | 1% Низкий | больше 3 лет назад | ||
GHSA-crhx-xmfj-53jv libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests. | 1% Низкий | около 3 лет назад | ||
GHSA-cr65-p662-fx5c phpMyAdmin vulnerable to Cross-site Scripting | CVSS3: 6.1 | 2% Низкий | около 3 лет назад | |
GHSA-cr49-5764-fxg4 phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers. | 0% Низкий | больше 3 лет назад | ||
GHSA-cq7h-9hgp-vpjq phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files. | 0% Низкий | около 3 лет назад | ||
GHSA-cq55-4q38-jxr8 An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object instantiation and autoloading. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-cj7j-6rg9-9523 Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-c9vh-vmq6-qhgr An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-c958-4j9x-q7w4 phpMyAdmin Cross-site Scripting (XSS) in the import dialog | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-c8wj-q36q-3wg4 phpMyAdmin Arbitrary file read vulnerability | CVSS3: 5.9 | 69% Средний | около 3 лет назад | |
GHSA-c5vr-rrqf-4hf2 Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) table sections. | 0% Низкий | около 3 лет назад | ||
GHSA-c2xg-74vm-x8g2 phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files. | 0% Низкий | больше 3 лет назад | ||
GHSA-9xhq-pm7v-693p phpMyAdmin Cryptographic Vulnerability | CVSS3: 5.3 | 0% Низкий | около 3 лет назад | |
GHSA-9xhj-74j8-9gxq phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-9rmm-8fp4-26hv phpMyAdmin Denial Of Service (DOS) attack | CVSS3: 7.5 | 2% Низкий | около 3 лет назад | |
GHSA-9qwv-267r-c7fq libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 1% Низкий | около 3 лет назад | ||
GHSA-9j9h-cpgc-8356 phpMyAdmin vulnerable to Cross-site Scripting | 0% Низкий | около 3 лет назад | ||
GHSA-9hrc-rwrq-v6mh phpMyAdmin DoS Vulnerability | CVSS3: 7.5 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу