Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

github логотип

GHSA-x394-g9j8-x7mf

больше 3 лет назад

phpMyAdmin Improper Authentication

CVSS3: 8.8
EPSS: Критический
github логотип

GHSA-x37v-98f9-mj32

больше 3 лет назад

phpMyAdmin SQL injection in Designer feature

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-wxxc-635g-7hm3

больше 3 лет назад

The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin.

EPSS: Низкий
github логотип

GHSA-wv8g-fx9j-q2jg

больше 3 лет назад

phpMyAdmin cross-site scripting Vulnerability via ENUM value

EPSS: Низкий
github логотип

GHSA-wpww-hx7x-xfjh

больше 3 лет назад

phpMyAdmin PHP code injection

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-wm9c-vcv2-vpqc

больше 3 лет назад

phpMyAdmin full path disclosure vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-wj42-52pv-wfj2

больше 3 лет назад

phpMyAdmin CRLF Injection Vulnerability

EPSS: Низкий
github логотип

GHSA-wh7g-3gvx-9g4r

больше 3 лет назад

phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.

EPSS: Низкий
github логотип

GHSA-wgmf-qh83-2587

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name.

EPSS: Низкий
github логотип

GHSA-wfw5-2vpg-7rjx

больше 3 лет назад

Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase </SCRIPT> end tag, which bypasses the protection against lowercase </script>.

EPSS: Низкий
github логотип

GHSA-wcmm-28rg-mg3r

больше 3 лет назад

phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file

EPSS: Низкий
github логотип

GHSA-wcjq-hpqg-qhvw

больше 3 лет назад

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the json_decode issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-wcgr-wpcg-82c8

больше 3 лет назад

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the PMA_shutdownDuringExport issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-w93p-25g8-q8w9

больше 3 лет назад

An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4) are affected.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-w8qg-j9fp-hrjf

больше 3 лет назад

phpMyAdmin Improper Input Validation

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-w4pm-q457-vx87

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.8.0.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors in unspecified scripts in the themes directory.

EPSS: Низкий
github логотип

GHSA-w3p2-mc39-r7v9

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted trigger name that is improperly handled on the database triggers page.

EPSS: Низкий
github логотип

GHSA-vxj6-pm6r-23hq

больше 3 лет назад

phpMyAdmin XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-vx8q-j7h9-vf6q

больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in PhpMyAdmin

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vwc7-2mqc-8723

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-x394-g9j8-x7mf

phpMyAdmin Improper Authentication

CVSS3: 8.8
94%
Критический
больше 3 лет назад
github логотип
GHSA-x37v-98f9-mj32

phpMyAdmin SQL injection in Designer feature

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-wxxc-635g-7hm3

The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-wv8g-fx9j-q2jg

phpMyAdmin cross-site scripting Vulnerability via ENUM value

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wpww-hx7x-xfjh

phpMyAdmin PHP code injection

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-wm9c-vcv2-vpqc

phpMyAdmin full path disclosure vulnerability

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-wj42-52pv-wfj2

phpMyAdmin CRLF Injection Vulnerability

1%
Низкий
больше 3 лет назад
github логотип
GHSA-wh7g-3gvx-9g4r

phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-wgmf-qh83-2587

Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-wfw5-2vpg-7rjx

Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase </SCRIPT> end tag, which bypasses the protection against lowercase </script>.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-wcmm-28rg-mg3r

phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file

1%
Низкий
больше 3 лет назад
github логотип
GHSA-wcjq-hpqg-qhvw

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the json_decode issue.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-wcgr-wpcg-82c8

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the PMA_shutdownDuringExport issue.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-w93p-25g8-q8w9

An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4) are affected.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-w8qg-j9fp-hrjf

phpMyAdmin Improper Input Validation

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-w4pm-q457-vx87

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.8.0.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors in unspecified scripts in the themes directory.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-w3p2-mc39-r7v9

Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted trigger name that is improperly handled on the database triggers page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-vxj6-pm6r-23hq

phpMyAdmin XSS Vulnerability

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-vx8q-j7h9-vf6q

Exposure of Sensitive Information to an Unauthorized Actor in PhpMyAdmin

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-vwc7-2mqc-8723

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу