Количество 1 093
Количество 1 093
GHSA-4c9q-64gq-xhx4
phpMyAdmin Cross-Site Request Forgery (CSRF)
GHSA-4953-8rw3-w7m5
show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.
GHSA-47r4-gvw9-7fw7
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.
GHSA-47qr-f86f-3wm4
phpMyAdmin DoS Vulnerability
GHSA-44vv-mm86-7cg6
phpMyAdmin server-side request forgery (SSRF)
GHSA-4458-ww2x-8wwm
Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.
GHSA-43mv-f787-vp98
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
GHSA-427m-jx2h-q45m
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.
GHSA-426q-975p-w5cr
phpMyAdmin Denial of service (DOS) attack with dbase extension
GHSA-3q28-xfw3-2q35
phpMyAdmin XSS Vulnerability
GHSA-3p87-w3c5-27gf
phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save
GHSA-3jmv-pqcg-4h64
SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter.
GHSA-3j5v-cjrg-phc7
SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.
GHSA-3hw5-fffc-qrg4
phpMyAdmin Denial of Service (DoS)
GHSA-3fgq-cmr4-97rr
phpMyAdmin CSS Injection Vulnerability
GHSA-395f-pvp5-hvp6
Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.
GHSA-3754-x86m-fj9m
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.
GHSA-372q-3c59-c2w9
Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an invalid SQL CREATE VIEW statement with a crafted name that triggers an error message.
GHSA-36hv-fqvj-3wq3
The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.
GHSA-2xg6-qhwr-gp7p
Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-4c9q-64gq-xhx4 phpMyAdmin Cross-Site Request Forgery (CSRF) | CVSS3: 6.5 | 25% Средний | около 3 лет назад | |
GHSA-4953-8rw3-w7m5 show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file. | 0% Низкий | около 3 лет назад | ||
GHSA-47r4-gvw9-7fw7 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action. | 0% Низкий | около 3 лет назад | ||
GHSA-47qr-f86f-3wm4 phpMyAdmin DoS Vulnerability | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
GHSA-44vv-mm86-7cg6 phpMyAdmin server-side request forgery (SSRF) | CVSS3: 8.6 | 0% Низкий | около 3 лет назад | |
GHSA-4458-ww2x-8wwm Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file. | 0% Низкий | около 3 лет назад | ||
GHSA-43mv-f787-vp98 phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-427m-jx2h-q45m Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code. | 0% Низкий | около 3 лет назад | ||
GHSA-426q-975p-w5cr phpMyAdmin Denial of service (DOS) attack with dbase extension | CVSS3: 5.9 | 1% Низкий | около 3 лет назад | |
GHSA-3q28-xfw3-2q35 phpMyAdmin XSS Vulnerability | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-3p87-w3c5-27gf phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save | 0% Низкий | около 3 лет назад | ||
GHSA-3jmv-pqcg-4h64 SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter. | 1% Низкий | больше 3 лет назад | ||
GHSA-3j5v-cjrg-phc7 SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter. | 1% Низкий | больше 3 лет назад | ||
GHSA-3hw5-fffc-qrg4 phpMyAdmin Denial of Service (DoS) | CVSS3: 5.9 | 1% Низкий | около 3 лет назад | |
GHSA-3fgq-cmr4-97rr phpMyAdmin CSS Injection Vulnerability | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-395f-pvp5-hvp6 Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files. | 1% Низкий | больше 3 лет назад | ||
GHSA-3754-x86m-fj9m Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977. | 7% Низкий | около 3 лет назад | ||
GHSA-372q-3c59-c2w9 Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an invalid SQL CREATE VIEW statement with a crafted name that triggers an error message. | 0% Низкий | около 3 лет назад | ||
GHSA-36hv-fqvj-3wq3 The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark. | 3% Низкий | около 3 лет назад | ||
GHSA-2xg6-qhwr-gp7p Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name. | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу