Количество 1 093
Количество 1 093

CVE-2019-19617
phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.

CVE-2019-19617
phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.
CVE-2019-19617
phpMyAdmin before 4.9.2 does not escape certain Git information, relat ...

CVE-2019-12922
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.

CVE-2019-12922
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
CVE-2019-12922
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in th ...

CVE-2019-12616
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.

CVE-2019-12616
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.
CVE-2019-12616
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability wa ...

CVE-2019-11768
An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.

CVE-2019-11768
An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.
CVE-2019-11768
An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability ...

CVE-2018-7260
Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVE-2018-7260
Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVE-2018-7260
Cross-site scripting (XSS) vulnerability in db_central_columns.php in ...

CVE-2018-19970
In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.

CVE-2018-19970
In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.
CVE-2018-19970
In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navi ...

CVE-2018-19969
phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.

CVE-2018-19969
phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2019-19617 phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php. | CVSS3: 9.8 | 1% Низкий | больше 5 лет назад |
![]() | CVE-2019-19617 phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php. | CVSS3: 9.8 | 1% Низкий | больше 5 лет назад |
CVE-2019-19617 phpMyAdmin before 4.9.2 does not escape certain Git information, relat ... | CVSS3: 9.8 | 1% Низкий | больше 5 лет назад | |
![]() | CVE-2019-12922 A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page. | CVSS3: 6.5 | 25% Средний | почти 6 лет назад |
![]() | CVE-2019-12922 A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page. | CVSS3: 6.5 | 25% Средний | почти 6 лет назад |
CVE-2019-12922 A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in th ... | CVSS3: 6.5 | 25% Средний | почти 6 лет назад | |
![]() | CVE-2019-12616 An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim. | CVSS3: 6.5 | 49% Средний | около 6 лет назад |
![]() | CVE-2019-12616 An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim. | CVSS3: 6.5 | 49% Средний | около 6 лет назад |
CVE-2019-12616 An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability wa ... | CVSS3: 6.5 | 49% Средний | около 6 лет назад | |
![]() | CVE-2019-11768 An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature. | CVSS3: 9.8 | 2% Низкий | около 6 лет назад |
![]() | CVE-2019-11768 An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature. | CVSS3: 9.8 | 2% Низкий | около 6 лет назад |
CVE-2019-11768 An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability ... | CVSS3: 9.8 | 2% Низкий | около 6 лет назад | |
![]() | CVE-2018-7260 Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | CVSS3: 5.4 | 0% Низкий | больше 7 лет назад |
![]() | CVE-2018-7260 Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | CVSS3: 5.4 | 0% Низкий | больше 7 лет назад |
CVE-2018-7260 Cross-site scripting (XSS) vulnerability in db_central_columns.php in ... | CVSS3: 5.4 | 0% Низкий | больше 7 лет назад | |
![]() | CVE-2018-19970 In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name. | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад |
![]() | CVE-2018-19970 In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name. | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад |
CVE-2018-19970 In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navi ... | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
![]() | CVE-2018-19969 phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc. | CVSS3: 8.8 | 0% Низкий | больше 6 лет назад |
![]() | CVE-2018-19969 phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc. | CVSS3: 8.8 | 0% Низкий | больше 6 лет назад |
Уязвимостей на страницу