Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

github логотип

GHSA-4c9q-64gq-xhx4

около 3 лет назад

phpMyAdmin Cross-Site Request Forgery (CSRF)

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-4953-8rw3-w7m5

около 3 лет назад

show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.

EPSS: Низкий
github логотип

GHSA-47r4-gvw9-7fw7

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.

EPSS: Низкий
github логотип

GHSA-47qr-f86f-3wm4

около 3 лет назад

phpMyAdmin DoS Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-44vv-mm86-7cg6

около 3 лет назад

phpMyAdmin server-side request forgery (SSRF)

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-4458-ww2x-8wwm

около 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

EPSS: Низкий
github логотип

GHSA-43mv-f787-vp98

больше 3 лет назад

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-427m-jx2h-q45m

около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-426q-975p-w5cr

около 3 лет назад

phpMyAdmin Denial of service (DOS) attack with dbase extension

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3q28-xfw3-2q35

около 3 лет назад

phpMyAdmin XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3p87-w3c5-27gf

около 3 лет назад

phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save

EPSS: Низкий
github логотип

GHSA-3jmv-pqcg-4h64

больше 3 лет назад

SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter.

EPSS: Низкий
github логотип

GHSA-3j5v-cjrg-phc7

больше 3 лет назад

SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.

EPSS: Низкий
github логотип

GHSA-3hw5-fffc-qrg4

около 3 лет назад

phpMyAdmin Denial of Service (DoS)

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3fgq-cmr4-97rr

около 3 лет назад

phpMyAdmin CSS Injection Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-395f-pvp5-hvp6

больше 3 лет назад

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

EPSS: Низкий
github логотип

GHSA-3754-x86m-fj9m

около 3 лет назад

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

EPSS: Низкий
github логотип

GHSA-372q-3c59-c2w9

около 3 лет назад

Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an invalid SQL CREATE VIEW statement with a crafted name that triggers an error message.

EPSS: Низкий
github логотип

GHSA-36hv-fqvj-3wq3

около 3 лет назад

The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.

EPSS: Низкий
github логотип

GHSA-2xg6-qhwr-gp7p

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4c9q-64gq-xhx4

phpMyAdmin Cross-Site Request Forgery (CSRF)

CVSS3: 6.5
25%
Средний
около 3 лет назад
github логотип
GHSA-4953-8rw3-w7m5

show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.

0%
Низкий
около 3 лет назад
github логотип
GHSA-47r4-gvw9-7fw7

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.

0%
Низкий
около 3 лет назад
github логотип
GHSA-47qr-f86f-3wm4

phpMyAdmin DoS Vulnerability

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-44vv-mm86-7cg6

phpMyAdmin server-side request forgery (SSRF)

CVSS3: 8.6
0%
Низкий
около 3 лет назад
github логотип
GHSA-4458-ww2x-8wwm

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

0%
Низкий
около 3 лет назад
github логотип
GHSA-43mv-f787-vp98

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-427m-jx2h-q45m

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

0%
Низкий
около 3 лет назад
github логотип
GHSA-426q-975p-w5cr

phpMyAdmin Denial of service (DOS) attack with dbase extension

CVSS3: 5.9
1%
Низкий
около 3 лет назад
github логотип
GHSA-3q28-xfw3-2q35

phpMyAdmin XSS Vulnerability

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-3p87-w3c5-27gf

phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save

0%
Низкий
около 3 лет назад
github логотип
GHSA-3jmv-pqcg-4h64

SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j5v-cjrg-phc7

SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hw5-fffc-qrg4

phpMyAdmin Denial of Service (DoS)

CVSS3: 5.9
1%
Низкий
около 3 лет назад
github логотип
GHSA-3fgq-cmr4-97rr

phpMyAdmin CSS Injection Vulnerability

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-395f-pvp5-hvp6

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3754-x86m-fj9m

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

7%
Низкий
около 3 лет назад
github логотип
GHSA-372q-3c59-c2w9

Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an invalid SQL CREATE VIEW statement with a crafted name that triggers an error message.

0%
Низкий
около 3 лет назад
github логотип
GHSA-36hv-fqvj-3wq3

The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.

3%
Низкий
около 3 лет назад
github логотип
GHSA-2xg6-qhwr-gp7p

Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу