Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

github логотип

GHSA-2vcq-4wwg-6wg7

больше 3 лет назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2v8p-xfj5-p29q

больше 3 лет назад

Cross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary web script or HTML via the db parameter in unknown scripts.

EPSS: Низкий
github логотип

GHSA-2v44-f984-3xpw

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.10.3 allow remote attackers to inject arbitrary web script or HTML via the (1) unlim_num_rows, (2) sql_query, or (3) pos parameter to (a) tbl_export.php; the (4) session_max_rows or (5) pos parameter to (b) sql.php; the (6) username parameter to (c) server_privileges.php; or the (7) sql_query parameter to (d) main.php. NOTE: vector 5 might be a regression or incomplete fix for CVE-2006-6942.7.

EPSS: Низкий
github логотип

GHSA-2p7v-jm8m-g3qq

около 3 лет назад

phpMyAdmin vulnerable to Cross-Site Request Forgery

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mcj-3r3r-v5wm

около 3 лет назад

phpMyAdmin DoS Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h23-c973-x63q

около 3 лет назад

phpMyAdmin Cross-site Scripting vulnerability

EPSS: Низкий
github логотип

GHSA-2cm4-w9vc-vwpc

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.

EPSS: Низкий
github логотип

GHSA-2c4q-6j77-737f

больше 3 лет назад

Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable).

EPSS: Низкий
github логотип

GHSA-28qp-wgp5-fp7m

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog.

EPSS: Низкий
github логотип

GHSA-282v-8gf3-6m78

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed.

EPSS: Низкий
ubuntu логотип

CVE-2023-25727

больше 2 лет назад

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2023-25727

больше 2 лет назад

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2023-25727

больше 2 лет назад

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated use ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-23808

больше 3 лет назад

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVSS3: 6.1
EPSS: Средний
nvd логотип

CVE-2022-23808

больше 3 лет назад

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVSS3: 6.1
EPSS: Средний
debian логотип

CVE-2022-23808

больше 3 лет назад

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker ca ...

CVSS3: 6.1
EPSS: Средний
ubuntu логотип

CVE-2022-23807

больше 3 лет назад

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-23807

больше 3 лет назад

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-23807

больше 3 лет назад

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0813

больше 3 лет назад

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vcq-4wwg-6wg7

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2v8p-xfj5-p29q

Cross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary web script or HTML via the db parameter in unknown scripts.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-2v44-f984-3xpw

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.10.3 allow remote attackers to inject arbitrary web script or HTML via the (1) unlim_num_rows, (2) sql_query, or (3) pos parameter to (a) tbl_export.php; the (4) session_max_rows or (5) pos parameter to (b) sql.php; the (6) username parameter to (c) server_privileges.php; or the (7) sql_query parameter to (d) main.php. NOTE: vector 5 might be a regression or incomplete fix for CVE-2006-6942.7.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p7v-jm8m-g3qq

phpMyAdmin vulnerable to Cross-Site Request Forgery

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2mcj-3r3r-v5wm

phpMyAdmin DoS Vulnerability

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2h23-c973-x63q

phpMyAdmin Cross-site Scripting vulnerability

0%
Низкий
около 3 лет назад
github логотип
GHSA-2cm4-w9vc-vwpc

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-2c4q-6j77-737f

Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-28qp-wgp5-fp7m

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-282v-8gf3-6m78

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed.

0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2023-25727

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.

CVSS3: 5.4
7%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-25727

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.

CVSS3: 5.4
7%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-25727

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated use ...

CVSS3: 5.4
7%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2022-23808

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVSS3: 6.1
67%
Средний
больше 3 лет назад
nvd логотип
CVE-2022-23808

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVSS3: 6.1
67%
Средний
больше 3 лет назад
debian логотип
CVE-2022-23808

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker ca ...

CVSS3: 6.1
67%
Средний
больше 3 лет назад
ubuntu логотип
CVE-2022-23807

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-23807

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-23807

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-0813

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу