Количество 1 095
Количество 1 095
GHSA-f6c3-pp9c-mrf5
Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.
GHSA-f47h-66wf-9744
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.
GHSA-cx7j-6x8v-hjf9
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.
GHSA-crhx-xmfj-53jv
libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
GHSA-cr65-p662-fx5c
phpMyAdmin vulnerable to Cross-site Scripting
GHSA-cr49-5764-fxg4
phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers.
GHSA-cq7h-9hgp-vpjq
phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.
GHSA-cq55-4q38-jxr8
An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object instantiation and autoloading. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
GHSA-cj7j-6rg9-9523
Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.
GHSA-c9vh-vmq6-qhgr
An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.
GHSA-c958-4j9x-q7w4
phpMyAdmin Cross-site Scripting (XSS) in the import dialog
GHSA-c8wj-q36q-3wg4
phpMyAdmin Arbitrary file read vulnerability
GHSA-c5vr-rrqf-4hf2
Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) table sections.
GHSA-c2xg-74vm-x8g2
phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files.
GHSA-9xhq-pm7v-693p
phpMyAdmin Cryptographic Vulnerability
GHSA-9xhj-74j8-9gxq
phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.
GHSA-9rmm-8fp4-26hv
phpMyAdmin Denial Of Service (DOS) attack
GHSA-9qwv-267r-c7fq
libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-9j9h-cpgc-8356
phpMyAdmin vulnerable to Cross-site Scripting
GHSA-9hrc-rwrq-v6mh
phpMyAdmin DoS Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-f6c3-pp9c-mrf5 Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link. | 0% Низкий | больше 3 лет назад | ||
GHSA-f47h-66wf-9744 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php. | 12% Средний | почти 4 года назад | ||
GHSA-cx7j-6x8v-hjf9 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function. | 2% Низкий | почти 4 года назад | ||
GHSA-crhx-xmfj-53jv libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests. | 1% Низкий | больше 3 лет назад | ||
GHSA-cr65-p662-fx5c phpMyAdmin vulnerable to Cross-site Scripting | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-cr49-5764-fxg4 phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers. | 0% Низкий | почти 4 года назад | ||
GHSA-cq7h-9hgp-vpjq phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files. | 0% Низкий | больше 3 лет назад | ||
GHSA-cq55-4q38-jxr8 An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object instantiation and autoloading. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-cj7j-6rg9-9523 Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-c9vh-vmq6-qhgr An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-c958-4j9x-q7w4 phpMyAdmin Cross-site Scripting (XSS) in the import dialog | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-c8wj-q36q-3wg4 phpMyAdmin Arbitrary file read vulnerability | CVSS3: 5.9 | 76% Высокий | больше 3 лет назад | |
GHSA-c5vr-rrqf-4hf2 Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) table sections. | 0% Низкий | больше 3 лет назад | ||
GHSA-c2xg-74vm-x8g2 phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files. | 0% Низкий | почти 4 года назад | ||
GHSA-9xhq-pm7v-693p phpMyAdmin Cryptographic Vulnerability | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-9xhj-74j8-9gxq phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-9rmm-8fp4-26hv phpMyAdmin Denial Of Service (DOS) attack | CVSS3: 7.5 | 3% Низкий | больше 3 лет назад | |
GHSA-9qwv-267r-c7fq libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 1% Низкий | больше 3 лет назад | ||
GHSA-9j9h-cpgc-8356 phpMyAdmin vulnerable to Cross-site Scripting | 0% Низкий | больше 3 лет назад | ||
GHSA-9hrc-rwrq-v6mh phpMyAdmin DoS Vulnerability | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу