Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

debian логотип

CVE-2018-19969

больше 6 лет назад

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a s ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2018-19968

больше 6 лет назад

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-19968

больше 6 лет назад

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-19968

больше 6 лет назад

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents o ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-15605

почти 7 лет назад

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-15605

почти 7 лет назад

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-15605

почти 7 лет назад

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scrip ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-12613

около 7 лет назад

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).

CVSS3: 8.8
EPSS: Критический
nvd логотип

CVE-2018-12613

около 7 лет назад

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).

CVSS3: 8.8
EPSS: Критический
debian логотип

CVE-2018-12613

около 7 лет назад

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an ...

CVSS3: 8.8
EPSS: Критический
ubuntu логотип

CVE-2018-12581

около 7 лет назад

An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-12581

около 7 лет назад

An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-12581

около 7 лет назад

An issue was discovered in js/designer/move.js in phpMyAdmin before 4. ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-10188

больше 7 лет назад

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-10188

больше 7 лет назад

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-10188

больше 7 лет назад

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to exec ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-18264

больше 7 лет назад

An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default). This occurs because some implementations of the PHP substr function return false when given '' as the first argument.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-18264

больше 7 лет назад

An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default). This occurs because some implementations of the PHP substr function return false when given '' as the first argument.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-18264

больше 7 лет назад

An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000499

больше 7 лет назад

phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2018-19969

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a s ...

CVSS3: 8.8
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-19968

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-19968

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-19968

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents o ...

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-15605

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2018-15605

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-15605

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scrip ...

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2018-12613

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).

CVSS3: 8.8
94%
Критический
около 7 лет назад
nvd логотип
CVE-2018-12613

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).

CVSS3: 8.8
94%
Критический
около 7 лет назад
debian логотип
CVE-2018-12613

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an ...

CVSS3: 8.8
94%
Критический
около 7 лет назад
ubuntu логотип
CVE-2018-12581

An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.

CVSS3: 6.1
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-12581

An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.

CVSS3: 6.1
1%
Низкий
около 7 лет назад
debian логотип
CVE-2018-12581

An issue was discovered in js/designer/move.js in phpMyAdmin before 4. ...

CVSS3: 6.1
1%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2018-10188

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-10188

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-10188

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to exec ...

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-18264

An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default). This occurs because some implementations of the PHP substr function return false when given '' as the first argument.

CVSS3: 9.8
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-18264

An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default). This occurs because some implementations of the PHP substr function return false when given '' as the first argument.

CVSS3: 9.8
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-18264

An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 ...

CVSS3: 9.8
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-1000499

phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.

CVSS3: 8.8
10%
Средний
больше 7 лет назад

Уязвимостей на страницу