Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

ubuntu логотип

CVE-2019-19617

больше 5 лет назад

phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-19617

больше 5 лет назад

phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-19617

больше 5 лет назад

phpMyAdmin before 4.9.2 does not escape certain Git information, relat ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2019-12922

почти 6 лет назад

A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2019-12922

почти 6 лет назад

A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2019-12922

почти 6 лет назад

A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in th ...

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2019-12616

около 6 лет назад

An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2019-12616

около 6 лет назад

An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2019-12616

около 6 лет назад

An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability wa ...

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2019-11768

около 6 лет назад

An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-11768

около 6 лет назад

An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-11768

около 6 лет назад

An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2018-7260

больше 7 лет назад

Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2018-7260

больше 7 лет назад

Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-7260

больше 7 лет назад

Cross-site scripting (XSS) vulnerability in db_central_columns.php in ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2018-19970

больше 6 лет назад

In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-19970

больше 6 лет назад

In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-19970

больше 6 лет назад

In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navi ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-19969

больше 6 лет назад

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-19969

больше 6 лет назад

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-19617

phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.

CVSS3: 9.8
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-19617

phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.

CVSS3: 9.8
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-19617

phpMyAdmin before 4.9.2 does not escape certain Git information, relat ...

CVSS3: 9.8
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-12922

A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.

CVSS3: 6.5
25%
Средний
почти 6 лет назад
nvd логотип
CVE-2019-12922

A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.

CVSS3: 6.5
25%
Средний
почти 6 лет назад
debian логотип
CVE-2019-12922

A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in th ...

CVSS3: 6.5
25%
Средний
почти 6 лет назад
ubuntu логотип
CVE-2019-12616

An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.

CVSS3: 6.5
49%
Средний
около 6 лет назад
nvd логотип
CVE-2019-12616

An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.

CVSS3: 6.5
49%
Средний
около 6 лет назад
debian логотип
CVE-2019-12616

An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability wa ...

CVSS3: 6.5
49%
Средний
около 6 лет назад
ubuntu логотип
CVE-2019-11768

An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.

CVSS3: 9.8
2%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-11768

An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.

CVSS3: 9.8
2%
Низкий
около 6 лет назад
debian логотип
CVE-2019-11768

An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability ...

CVSS3: 9.8
2%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2018-7260

Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS3: 5.4
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-7260

Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS3: 5.4
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-7260

Cross-site scripting (XSS) vulnerability in db_central_columns.php in ...

CVSS3: 5.4
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-19970

In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19970

In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-19970

In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navi ...

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-19969

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.

CVSS3: 8.8
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19969

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.

CVSS3: 8.8
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу