Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

github логотип

GHSA-x394-g9j8-x7mf

около 3 лет назад

phpMyAdmin Improper Authentication

CVSS3: 8.8
EPSS: Критический
github логотип

GHSA-x37v-98f9-mj32

около 3 лет назад

phpMyAdmin SQL injection in Designer feature

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-wxxc-635g-7hm3

больше 3 лет назад

The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin.

EPSS: Низкий
github логотип

GHSA-wv8g-fx9j-q2jg

около 3 лет назад

phpMyAdmin cross-site scripting Vulnerability via ENUM value

EPSS: Низкий
github логотип

GHSA-wpww-hx7x-xfjh

около 3 лет назад

phpMyAdmin PHP code injection

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-wm9c-vcv2-vpqc

около 3 лет назад

phpMyAdmin full path disclosure vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-wj42-52pv-wfj2

больше 3 лет назад

phpMyAdmin CRLF Injection Vulnerability

EPSS: Низкий
github логотип

GHSA-wh7g-3gvx-9g4r

около 3 лет назад

phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.

EPSS: Низкий
github логотип

GHSA-wgmf-qh83-2587

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name.

EPSS: Низкий
github логотип

GHSA-wfw5-2vpg-7rjx

больше 3 лет назад

Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase </SCRIPT> end tag, which bypasses the protection against lowercase </script>.

EPSS: Низкий
github логотип

GHSA-wcmm-28rg-mg3r

около 3 лет назад

phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file

EPSS: Низкий
github логотип

GHSA-wcjq-hpqg-qhvw

около 3 лет назад

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the json_decode issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-wcgr-wpcg-82c8

около 3 лет назад

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the PMA_shutdownDuringExport issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-w93p-25g8-q8w9

около 3 лет назад

An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4) are affected.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-w8qg-j9fp-hrjf

около 3 лет назад

phpMyAdmin Improper Input Validation

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-w4pm-q457-vx87

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.8.0.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors in unspecified scripts in the themes directory.

EPSS: Низкий
github логотип

GHSA-w3p2-mc39-r7v9

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted trigger name that is improperly handled on the database triggers page.

EPSS: Низкий
github логотип

GHSA-vxj6-pm6r-23hq

около 3 лет назад

phpMyAdmin XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-vx8q-j7h9-vf6q

больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in PhpMyAdmin

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vwc7-2mqc-8723

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-x394-g9j8-x7mf

phpMyAdmin Improper Authentication

CVSS3: 8.8
94%
Критический
около 3 лет назад
github логотип
GHSA-x37v-98f9-mj32

phpMyAdmin SQL injection in Designer feature

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-wxxc-635g-7hm3

The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-wv8g-fx9j-q2jg

phpMyAdmin cross-site scripting Vulnerability via ENUM value

0%
Низкий
около 3 лет назад
github логотип
GHSA-wpww-hx7x-xfjh

phpMyAdmin PHP code injection

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-wm9c-vcv2-vpqc

phpMyAdmin full path disclosure vulnerability

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-wj42-52pv-wfj2

phpMyAdmin CRLF Injection Vulnerability

1%
Низкий
больше 3 лет назад
github логотип
GHSA-wh7g-3gvx-9g4r

phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.

2%
Низкий
около 3 лет назад
github логотип
GHSA-wgmf-qh83-2587

Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name.

1%
Низкий
около 3 лет назад
github логотип
GHSA-wfw5-2vpg-7rjx

Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase </SCRIPT> end tag, which bypasses the protection against lowercase </script>.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-wcmm-28rg-mg3r

phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file

1%
Низкий
около 3 лет назад
github логотип
GHSA-wcjq-hpqg-qhvw

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the json_decode issue.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-wcgr-wpcg-82c8

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the PMA_shutdownDuringExport issue.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-w93p-25g8-q8w9

An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4) are affected.

CVSS3: 8.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-w8qg-j9fp-hrjf

phpMyAdmin Improper Input Validation

CVSS3: 6.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-w4pm-q457-vx87

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.8.0.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors in unspecified scripts in the themes directory.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-w3p2-mc39-r7v9

Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted trigger name that is improperly handled on the database triggers page.

0%
Низкий
около 3 лет назад
github логотип
GHSA-vxj6-pm6r-23hq

phpMyAdmin XSS Vulnerability

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-vx8q-j7h9-vf6q

Exposure of Sensitive Information to an Unauthorized Actor in PhpMyAdmin

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-vwc7-2mqc-8723

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php.

1%
Низкий
около 3 лет назад

Уязвимостей на страницу