Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 095

Количество 1 095

github логотип

GHSA-2vcq-4wwg-6wg7

почти 4 года назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2v8p-xfj5-p29q

почти 4 года назад

Cross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary web script or HTML via the db parameter in unknown scripts.

EPSS: Низкий
github логотип

GHSA-2v44-f984-3xpw

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.10.3 allow remote attackers to inject arbitrary web script or HTML via the (1) unlim_num_rows, (2) sql_query, or (3) pos parameter to (a) tbl_export.php; the (4) session_max_rows or (5) pos parameter to (b) sql.php; the (6) username parameter to (c) server_privileges.php; or the (7) sql_query parameter to (d) main.php. NOTE: vector 5 might be a regression or incomplete fix for CVE-2006-6942.7.

EPSS: Низкий
github логотип

GHSA-2p7v-jm8m-g3qq

больше 3 лет назад

phpMyAdmin vulnerable to Cross-Site Request Forgery

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mcj-3r3r-v5wm

больше 3 лет назад

phpMyAdmin DoS Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h23-c973-x63q

больше 3 лет назад

phpMyAdmin Cross-site Scripting vulnerability

EPSS: Низкий
github логотип

GHSA-2cm4-w9vc-vwpc

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.

EPSS: Средний
github логотип

GHSA-2c4q-6j77-737f

почти 4 года назад

Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable).

EPSS: Низкий
github логотип

GHSA-28qp-wgp5-fp7m

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog.

EPSS: Низкий
github логотип

GHSA-282v-8gf3-6m78

почти 4 года назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed.

EPSS: Низкий
ubuntu логотип

CVE-2023-25727

почти 3 года назад

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2023-25727

почти 3 года назад

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2023-25727

почти 3 года назад

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated use ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-23808

около 4 лет назад

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVSS3: 6.1
EPSS: Средний
nvd логотип

CVE-2022-23808

около 4 лет назад

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVSS3: 6.1
EPSS: Средний
debian логотип

CVE-2022-23808

около 4 лет назад

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker ca ...

CVSS3: 6.1
EPSS: Средний
ubuntu логотип

CVE-2022-23807

около 4 лет назад

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-23807

около 4 лет назад

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-23807

около 4 лет назад

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-0813

почти 4 года назад

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vcq-4wwg-6wg7

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2v8p-xfj5-p29q

Cross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary web script or HTML via the db parameter in unknown scripts.

4%
Низкий
почти 4 года назад
github логотип
GHSA-2v44-f984-3xpw

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.10.3 allow remote attackers to inject arbitrary web script or HTML via the (1) unlim_num_rows, (2) sql_query, or (3) pos parameter to (a) tbl_export.php; the (4) session_max_rows or (5) pos parameter to (b) sql.php; the (6) username parameter to (c) server_privileges.php; or the (7) sql_query parameter to (d) main.php. NOTE: vector 5 might be a regression or incomplete fix for CVE-2006-6942.7.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2p7v-jm8m-g3qq

phpMyAdmin vulnerable to Cross-Site Request Forgery

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2mcj-3r3r-v5wm

phpMyAdmin DoS Vulnerability

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2h23-c973-x63q

phpMyAdmin Cross-site Scripting vulnerability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cm4-w9vc-vwpc

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.

12%
Средний
почти 4 года назад
github логотип
GHSA-2c4q-6j77-737f

Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable).

1%
Низкий
почти 4 года назад
github логотип
GHSA-28qp-wgp5-fp7m

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog.

0%
Низкий
почти 4 года назад
github логотип
GHSA-282v-8gf3-6m78

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed.

0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2023-25727

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.

CVSS3: 5.4
8%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-25727

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.

CVSS3: 5.4
8%
Низкий
почти 3 года назад
debian логотип
CVE-2023-25727

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated use ...

CVSS3: 5.4
8%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-23808

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVSS3: 6.1
68%
Средний
около 4 лет назад
nvd логотип
CVE-2022-23808

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

CVSS3: 6.1
68%
Средний
около 4 лет назад
debian логотип
CVE-2022-23808

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker ca ...

CVSS3: 6.1
68%
Средний
около 4 лет назад
ubuntu логотип
CVE-2022-23807

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-23807

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-23807

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-0813

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.

CVSS3: 5.3
0%
Низкий
почти 4 года назад

Уязвимостей на страницу