Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

nvd логотип

CVE-2022-0813

больше 3 лет назад

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-0813

больше 3 лет назад

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-5504

больше 5 лет назад

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

CVSS3: 8.8
EPSS: Средний
nvd логотип

CVE-2020-5504

больше 5 лет назад

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

CVSS3: 8.8
EPSS: Средний
debian логотип

CVE-2020-5504

больше 5 лет назад

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists ...

CVSS3: 8.8
EPSS: Средний
ubuntu логотип

CVE-2020-22452

больше 2 лет назад

SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2020-22452

больше 2 лет назад

SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2020-22452

больше 2 лет назад

SQL Injection vulnerability in function getTableCreationQuery in Creat ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2020-22278

почти 5 лет назад

phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-22278

почти 5 лет назад

phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-22278

почти 5 лет назад

phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2020-11441

больше 5 лет назад

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-11441

больше 5 лет назад

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-11441

больше 5 лет назад

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astrin ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-6799

больше 6 лет назад

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.

CVSS3: 5.9
EPSS: Средний
nvd логотип

CVE-2019-6799

больше 6 лет назад

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.

CVSS3: 5.9
EPSS: Средний
debian логотип

CVE-2019-6799

больше 6 лет назад

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbi ...

CVSS3: 5.9
EPSS: Средний
ubuntu логотип

CVE-2019-6798

больше 6 лет назад

An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-6798

больше 6 лет назад

An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-6798

больше 6 лет назад

An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability wa ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-0813

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-0813

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially ...

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2020-5504

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

CVSS3: 8.8
14%
Средний
больше 5 лет назад
nvd логотип
CVE-2020-5504

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

CVSS3: 8.8
14%
Средний
больше 5 лет назад
debian логотип
CVE-2020-5504

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists ...

CVSS3: 8.8
14%
Средний
больше 5 лет назад
ubuntu логотип
CVE-2020-22452

SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.

CVSS3: 9.8
3%
Низкий
больше 2 лет назад
nvd логотип
CVE-2020-22452

SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.

CVSS3: 9.8
3%
Низкий
больше 2 лет назад
debian логотип
CVE-2020-22452

SQL Injection vulnerability in function getTableCreationQuery in Creat ...

CVSS3: 9.8
3%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2020-22278

phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.

CVSS3: 8.8
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-22278

phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.

CVSS3: 8.8
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-22278

phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE ...

CVSS3: 8.8
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2020-11441

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.

CVSS3: 6.1
2%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-11441

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.

CVSS3: 6.1
2%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-11441

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astrin ...

CVSS3: 6.1
2%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-6799

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.

CVSS3: 5.9
69%
Средний
больше 6 лет назад
nvd логотип
CVE-2019-6799

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.

CVSS3: 5.9
69%
Средний
больше 6 лет назад
debian логотип
CVE-2019-6799

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbi ...

CVSS3: 5.9
69%
Средний
больше 6 лет назад
ubuntu логотип
CVE-2019-6798

An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-6798

An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-6798

An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability wa ...

CVSS3: 9.8
1%
Низкий
больше 6 лет назад

Уязвимостей на страницу