Количество 1 093
Количество 1 093
GHSA-678w-6p5f-47x3
An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
GHSA-6723-jq8x-794g
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992.
GHSA-6442-8w69-mgwm
The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.
GHSA-5vmc-9jj9-45xc
An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
GHSA-5r36-wxjq-vcfh
An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the file generator_plugin.sh. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
GHSA-5pvv-f8h3-gw96
phpMyAdmin Cross-site Scripting In MySQL Table Name
GHSA-5pmg-qh2c-7j24
phpMyAdmin allows remote attackers to spoof content via the url parameter
GHSA-5p69-rmx8-7gw7
phpMyAdmin Multiple XSS Vulnerabilities
GHSA-5h5m-fj48-qpjw
phpMyAdmin Open Redirect
GHSA-5gh4-v2ch-pcx4
phpMyAdmin Multiple cross-site scripting (XSS) vulnerabilities
GHSA-5868-g58j-vrj5
phpMyAdmin Improper Privilege Management
GHSA-567r-vqj7-5cw7
phpMyAdmin Authentication Bypass
GHSA-553h-m986-4mxc
Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web script or HTML via UTF-7 or US-ASCII encoded characters, which are injected into an error message, as demonstrated by a request with a utf7 charset parameter accompanied by UTF-7 data.
GHSA-52wv-2qwp-5w9x
Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.
GHSA-4q58-5x28-53wv
phpMyAdmin Vulnerable to Cross-Site Scripting
GHSA-4phh-wxc8-pcp3
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted database name, (2) a crafted user name, (3) a crafted logo URL in the navigation panel, (4) a crafted entry in a certain proxy list, or (5) crafted content in a version.json file.
GHSA-4m4p-5pj4-3gv8
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter.
GHSA-4jh6-gh8q-jcwr
Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.
GHSA-4gv8-hhx3-rq62
An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
GHSA-4gmg-gwjh-3mmr
phpMyAdmin Cryptographic Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-678w-6p5f-47x3 An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 8.8 | 0% Низкий | около 3 лет назад | |
GHSA-6723-jq8x-794g Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992. | 0% Низкий | больше 3 лет назад | ||
GHSA-6442-8w69-mgwm The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request. | 1% Низкий | около 3 лет назад | ||
GHSA-5vmc-9jj9-45xc An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-5r36-wxjq-vcfh An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the file generator_plugin.sh. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 7.5 | 4% Низкий | около 3 лет назад | |
GHSA-5pvv-f8h3-gw96 phpMyAdmin Cross-site Scripting In MySQL Table Name | 3% Низкий | больше 3 лет назад | ||
GHSA-5pmg-qh2c-7j24 phpMyAdmin allows remote attackers to spoof content via the url parameter | 1% Низкий | около 3 лет назад | ||
GHSA-5p69-rmx8-7gw7 phpMyAdmin Multiple XSS Vulnerabilities | 0% Низкий | около 3 лет назад | ||
GHSA-5h5m-fj48-qpjw phpMyAdmin Open Redirect | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-5gh4-v2ch-pcx4 phpMyAdmin Multiple cross-site scripting (XSS) vulnerabilities | 0% Низкий | около 3 лет назад | ||
GHSA-5868-g58j-vrj5 phpMyAdmin Improper Privilege Management | CVSS3: 9.8 | 0% Низкий | около 3 лет назад | |
GHSA-567r-vqj7-5cw7 phpMyAdmin Authentication Bypass | CVSS3: 9.8 | 0% Низкий | около 3 лет назад | |
GHSA-553h-m986-4mxc Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web script or HTML via UTF-7 or US-ASCII encoded characters, which are injected into an error message, as demonstrated by a request with a utf7 charset parameter accompanied by UTF-7 data. | 1% Низкий | больше 3 лет назад | ||
GHSA-52wv-2qwp-5w9x Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value. | 1% Низкий | около 3 лет назад | ||
GHSA-4q58-5x28-53wv phpMyAdmin Vulnerable to Cross-Site Scripting | 0% Низкий | около 3 лет назад | ||
GHSA-4phh-wxc8-pcp3 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted database name, (2) a crafted user name, (3) a crafted logo URL in the navigation panel, (4) a crafted entry in a certain proxy list, or (5) crafted content in a version.json file. | 0% Низкий | около 3 лет назад | ||
GHSA-4m4p-5pj4-3gv8 Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter. | 8% Низкий | больше 3 лет назад | ||
GHSA-4jh6-gh8q-jcwr Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script. | 1% Низкий | больше 3 лет назад | ||
GHSA-4gv8-hhx3-rq62 An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад | |
GHSA-4gmg-gwjh-3mmr phpMyAdmin Cryptographic Vulnerability | CVSS3: 7.5 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу