Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

github логотип

GHSA-f6c3-pp9c-mrf5

около 3 лет назад

Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.

EPSS: Низкий
github логотип

GHSA-f47h-66wf-9744

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.

EPSS: Средний
github логотип

GHSA-cx7j-6x8v-hjf9

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.

EPSS: Низкий
github логотип

GHSA-crhx-xmfj-53jv

около 3 лет назад

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

EPSS: Низкий
github логотип

GHSA-cr65-p662-fx5c

около 3 лет назад

phpMyAdmin vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-cr49-5764-fxg4

больше 3 лет назад

phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers.

EPSS: Низкий
github логотип

GHSA-cq7h-9hgp-vpjq

около 3 лет назад

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.

EPSS: Низкий
github логотип

GHSA-cq55-4q38-jxr8

около 3 лет назад

An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object instantiation and autoloading. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cj7j-6rg9-9523

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.

EPSS: Низкий
github логотип

GHSA-c9vh-vmq6-qhgr

около 3 лет назад

An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c958-4j9x-q7w4

около 3 лет назад

phpMyAdmin Cross-site Scripting (XSS) in the import dialog

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-c8wj-q36q-3wg4

около 3 лет назад

phpMyAdmin Arbitrary file read vulnerability

CVSS3: 5.9
EPSS: Средний
github логотип

GHSA-c5vr-rrqf-4hf2

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) table sections.

EPSS: Низкий
github логотип

GHSA-c2xg-74vm-x8g2

больше 3 лет назад

phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files.

EPSS: Низкий
github логотип

GHSA-9xhq-pm7v-693p

около 3 лет назад

phpMyAdmin Cryptographic Vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9xhj-74j8-9gxq

больше 3 лет назад

phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.

EPSS: Низкий
github логотип

GHSA-9rmm-8fp4-26hv

около 3 лет назад

phpMyAdmin Denial Of Service (DOS) attack

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9qwv-267r-c7fq

около 3 лет назад

libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-9j9h-cpgc-8356

около 3 лет назад

phpMyAdmin vulnerable to Cross-site Scripting

EPSS: Низкий
github логотип

GHSA-9hrc-rwrq-v6mh

около 3 лет назад

phpMyAdmin DoS Vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-f6c3-pp9c-mrf5

Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.

0%
Низкий
около 3 лет назад
github логотип
GHSA-f47h-66wf-9744

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.

13%
Средний
больше 3 лет назад
github логотип
GHSA-cx7j-6x8v-hjf9

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-crhx-xmfj-53jv

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

1%
Низкий
около 3 лет назад
github логотип
GHSA-cr65-p662-fx5c

phpMyAdmin vulnerable to Cross-site Scripting

CVSS3: 6.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-cr49-5764-fxg4

phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cq7h-9hgp-vpjq

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.

0%
Низкий
около 3 лет назад
github логотип
GHSA-cq55-4q38-jxr8

An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution because of the interaction with object instantiation and autoloading. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-cj7j-6rg9-9523

Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-c9vh-vmq6-qhgr

An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-c958-4j9x-q7w4

phpMyAdmin Cross-site Scripting (XSS) in the import dialog

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-c8wj-q36q-3wg4

phpMyAdmin Arbitrary file read vulnerability

CVSS3: 5.9
69%
Средний
около 3 лет назад
github логотип
GHSA-c5vr-rrqf-4hf2

Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) table sections.

0%
Низкий
около 3 лет назад
github логотип
GHSA-c2xg-74vm-x8g2

phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9xhq-pm7v-693p

phpMyAdmin Cryptographic Vulnerability

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-9xhj-74j8-9gxq

phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9rmm-8fp4-26hv

phpMyAdmin Denial Of Service (DOS) attack

CVSS3: 7.5
2%
Низкий
около 3 лет назад
github логотип
GHSA-9qwv-267r-c7fq

libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

1%
Низкий
около 3 лет назад
github логотип
GHSA-9j9h-cpgc-8356

phpMyAdmin vulnerable to Cross-site Scripting

0%
Низкий
около 3 лет назад
github логотип
GHSA-9hrc-rwrq-v6mh

phpMyAdmin DoS Vulnerability

CVSS3: 7.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу