Количество 1 093
Количество 1 093
GHSA-x394-g9j8-x7mf
phpMyAdmin Improper Authentication
GHSA-x37v-98f9-mj32
phpMyAdmin SQL injection in Designer feature
GHSA-wxxc-635g-7hm3
The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin.
GHSA-wv8g-fx9j-q2jg
phpMyAdmin cross-site scripting Vulnerability via ENUM value
GHSA-wpww-hx7x-xfjh
phpMyAdmin PHP code injection
GHSA-wm9c-vcv2-vpqc
phpMyAdmin full path disclosure vulnerability
GHSA-wj42-52pv-wfj2
phpMyAdmin CRLF Injection Vulnerability
GHSA-wh7g-3gvx-9g4r
phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.
GHSA-wgmf-qh83-2587
Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name.
GHSA-wfw5-2vpg-7rjx
Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase </SCRIPT> end tag, which bypasses the protection against lowercase </script>.
GHSA-wcmm-28rg-mg3r
phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file
GHSA-wcjq-hpqg-qhvw
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the json_decode issue.
GHSA-wcgr-wpcg-82c8
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the PMA_shutdownDuringExport issue.
GHSA-w93p-25g8-q8w9
An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4) are affected.
GHSA-w8qg-j9fp-hrjf
phpMyAdmin Improper Input Validation
GHSA-w4pm-q457-vx87
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.8.0.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors in unspecified scripts in the themes directory.
GHSA-w3p2-mc39-r7v9
Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted trigger name that is improperly handled on the database triggers page.
GHSA-vxj6-pm6r-23hq
phpMyAdmin XSS Vulnerability
GHSA-vx8q-j7h9-vf6q
Exposure of Sensitive Information to an Unauthorized Actor in PhpMyAdmin
GHSA-vwc7-2mqc-8723
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-x394-g9j8-x7mf phpMyAdmin Improper Authentication | CVSS3: 8.8 | 94% Критический | около 3 лет назад | |
GHSA-x37v-98f9-mj32 phpMyAdmin SQL injection in Designer feature | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-wxxc-635g-7hm3 The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin. | 1% Низкий | больше 3 лет назад | ||
GHSA-wv8g-fx9j-q2jg phpMyAdmin cross-site scripting Vulnerability via ENUM value | 0% Низкий | около 3 лет назад | ||
GHSA-wpww-hx7x-xfjh phpMyAdmin PHP code injection | CVSS3: 8.8 | 0% Низкий | около 3 лет назад | |
GHSA-wm9c-vcv2-vpqc phpMyAdmin full path disclosure vulnerability | CVSS3: 5.3 | 1% Низкий | около 3 лет назад | |
GHSA-wj42-52pv-wfj2 phpMyAdmin CRLF Injection Vulnerability | 1% Низкий | больше 3 лет назад | ||
GHSA-wh7g-3gvx-9g4r phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php. | 2% Низкий | около 3 лет назад | ||
GHSA-wgmf-qh83-2587 Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name. | 1% Низкий | около 3 лет назад | ||
GHSA-wfw5-2vpg-7rjx Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase </SCRIPT> end tag, which bypasses the protection against lowercase </script>. | 1% Низкий | больше 3 лет назад | ||
GHSA-wcmm-28rg-mg3r phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file | 1% Низкий | около 3 лет назад | ||
GHSA-wcjq-hpqg-qhvw An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the json_decode issue. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад | |
GHSA-wcgr-wpcg-82c8 An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the PMA_shutdownDuringExport issue. | CVSS3: 5.3 | 1% Низкий | около 3 лет назад | |
GHSA-w93p-25g8-q8w9 An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4) are affected. | CVSS3: 8.1 | 0% Низкий | около 3 лет назад | |
GHSA-w8qg-j9fp-hrjf phpMyAdmin Improper Input Validation | CVSS3: 6.8 | 0% Низкий | около 3 лет назад | |
GHSA-w4pm-q457-vx87 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.8.0.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors in unspecified scripts in the themes directory. | 1% Низкий | больше 3 лет назад | ||
GHSA-w3p2-mc39-r7v9 Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted trigger name that is improperly handled on the database triggers page. | 0% Низкий | около 3 лет назад | ||
GHSA-vxj6-pm6r-23hq phpMyAdmin XSS Vulnerability | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-vx8q-j7h9-vf6q Exposure of Sensitive Information to an Unauthorized Actor in PhpMyAdmin | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-vwc7-2mqc-8723 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php. | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу