Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 095

Количество 1 095

github логотип

GHSA-f6c3-pp9c-mrf5

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.

EPSS: Низкий
github логотип

GHSA-f47h-66wf-9744

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.

EPSS: Средний
github логотип

GHSA-cx7j-6x8v-hjf9

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.

EPSS: Низкий
github логотип

GHSA-crhx-xmfj-53jv

больше 3 лет назад

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

EPSS: Низкий
github логотип

GHSA-cr65-p662-fx5c

больше 3 лет назад

phpMyAdmin vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-cr49-5764-fxg4

почти 4 года назад

phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers.

EPSS: Низкий
github логотип

GHSA-cq7h-9hgp-vpjq

больше 3 лет назад

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.

EPSS: Низкий
github логотип

GHSA-cq55-4q38-jxr8

больше 3 лет назад

An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object instantiation and autoloading. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cj7j-6rg9-9523

почти 4 года назад

Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.

EPSS: Низкий
github логотип

GHSA-c9vh-vmq6-qhgr

больше 3 лет назад

An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c958-4j9x-q7w4

больше 3 лет назад

phpMyAdmin Cross-site Scripting (XSS) in the import dialog

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-c8wj-q36q-3wg4

больше 3 лет назад

phpMyAdmin Arbitrary file read vulnerability

CVSS3: 5.9
EPSS: Высокий
github логотип

GHSA-c5vr-rrqf-4hf2

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) table sections.

EPSS: Низкий
github логотип

GHSA-c2xg-74vm-x8g2

почти 4 года назад

phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files.

EPSS: Низкий
github логотип

GHSA-9xhq-pm7v-693p

больше 3 лет назад

phpMyAdmin Cryptographic Vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9xhj-74j8-9gxq

почти 4 года назад

phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.

EPSS: Низкий
github логотип

GHSA-9rmm-8fp4-26hv

больше 3 лет назад

phpMyAdmin Denial Of Service (DOS) attack

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9qwv-267r-c7fq

больше 3 лет назад

libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-9j9h-cpgc-8356

больше 3 лет назад

phpMyAdmin vulnerable to Cross-site Scripting

EPSS: Низкий
github логотип

GHSA-9hrc-rwrq-v6mh

больше 3 лет назад

phpMyAdmin DoS Vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-f6c3-pp9c-mrf5

Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-f47h-66wf-9744

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.

12%
Средний
почти 4 года назад
github логотип
GHSA-cx7j-6x8v-hjf9

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.

2%
Низкий
почти 4 года назад
github логотип
GHSA-crhx-xmfj-53jv

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-cr65-p662-fx5c

phpMyAdmin vulnerable to Cross-site Scripting

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-cr49-5764-fxg4

phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers.

0%
Низкий
почти 4 года назад
github логотип
GHSA-cq7h-9hgp-vpjq

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cq55-4q38-jxr8

An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object instantiation and autoloading. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-cj7j-6rg9-9523

Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-c9vh-vmq6-qhgr

An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-c958-4j9x-q7w4

phpMyAdmin Cross-site Scripting (XSS) in the import dialog

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-c8wj-q36q-3wg4

phpMyAdmin Arbitrary file read vulnerability

CVSS3: 5.9
76%
Высокий
больше 3 лет назад
github логотип
GHSA-c5vr-rrqf-4hf2

Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) table sections.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-c2xg-74vm-x8g2

phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-9xhq-pm7v-693p

phpMyAdmin Cryptographic Vulnerability

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9xhj-74j8-9gxq

phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-9rmm-8fp4-26hv

phpMyAdmin Denial Of Service (DOS) attack

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-9qwv-267r-c7fq

libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-9j9h-cpgc-8356

phpMyAdmin vulnerable to Cross-site Scripting

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9hrc-rwrq-v6mh

phpMyAdmin DoS Vulnerability

CVSS3: 7.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу