Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 095

Количество 1 095

debian логотип

CVE-2018-19969

около 7 лет назад

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a s ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2018-19968

около 7 лет назад

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-19968

около 7 лет назад

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-19968

около 7 лет назад

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents o ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-15605

больше 7 лет назад

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-15605

больше 7 лет назад

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-15605

больше 7 лет назад

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scrip ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-12613

больше 7 лет назад

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).

CVSS3: 8.8
EPSS: Критический
nvd логотип

CVE-2018-12613

больше 7 лет назад

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).

CVSS3: 8.8
EPSS: Критический
debian логотип

CVE-2018-12613

больше 7 лет назад

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an ...

CVSS3: 8.8
EPSS: Критический
ubuntu логотип

CVE-2018-12581

больше 7 лет назад

An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-12581

больше 7 лет назад

An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-12581

больше 7 лет назад

An issue was discovered in js/designer/move.js in phpMyAdmin before 4. ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2018-10188

почти 8 лет назад

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-10188

почти 8 лет назад

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-10188

почти 8 лет назад

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to exec ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-18264

почти 8 лет назад

An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default). This occurs because some implementations of the PHP substr function return false when given '' as the first argument.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-18264

почти 8 лет назад

An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default). This occurs because some implementations of the PHP substr function return false when given '' as the first argument.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-18264

почти 8 лет назад

An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000499

около 8 лет назад

phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2018-19969

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a s ...

CVSS3: 8.8
0%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2018-19968

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

CVSS3: 6.5
3%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-19968

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

CVSS3: 6.5
3%
Низкий
около 7 лет назад
debian логотип
CVE-2018-19968

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents o ...

CVSS3: 6.5
3%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2018-15605

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.

CVSS3: 6.1
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-15605

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.

CVSS3: 6.1
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-15605

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scrip ...

CVSS3: 6.1
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-12613

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).

CVSS3: 8.8
94%
Критический
больше 7 лет назад
nvd логотип
CVE-2018-12613

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).

CVSS3: 8.8
94%
Критический
больше 7 лет назад
debian логотип
CVE-2018-12613

An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an ...

CVSS3: 8.8
94%
Критический
больше 7 лет назад
ubuntu логотип
CVE-2018-12581

An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.

CVSS3: 6.1
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12581

An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.

CVSS3: 6.1
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12581

An issue was discovered in js/designer/move.js in phpMyAdmin before 4. ...

CVSS3: 6.1
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-10188

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.

CVSS3: 8.8
1%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-10188

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.

CVSS3: 8.8
1%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-10188

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to exec ...

CVSS3: 8.8
1%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2017-18264

An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default). This occurs because some implementations of the PHP substr function return false when given '' as the first argument.

CVSS3: 9.8
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-18264

An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., version 5). This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default). This occurs because some implementations of the PHP substr function return false when given '' as the first argument.

CVSS3: 9.8
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-18264

An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 ...

CVSS3: 9.8
0%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2017-1000499

phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.

CVSS3: 8.8
11%
Средний
около 8 лет назад

Уязвимостей на страницу