Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 095

Количество 1 095

ubuntu логотип

CVE-2016-9866

около 9 лет назад

An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-9866

около 9 лет назад

An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-9866

около 9 лет назад

An issue was discovered in phpMyAdmin. When the arg_separator is diffe ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-9865

около 9 лет назад

An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-9865

около 9 лет назад

An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-9865

около 9 лет назад

An issue was discovered in phpMyAdmin. Due to a bug in serialized stri ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-9864

около 9 лет назад

An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-9864

около 9 лет назад

An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-9864

около 9 лет назад

An issue was discovered in phpMyAdmin. With a crafted username or a ta ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9863

около 9 лет назад

An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) attack. All 4.6.x versions (prior to 4.6.5) are affected.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-9863

около 9 лет назад

An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) attack. All 4.6.x versions (prior to 4.6.5) are affected.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-9863

около 9 лет назад

An issue was discovered in phpMyAdmin. With a very large request to ta ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9862

около 9 лет назад

An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-9862

около 9 лет назад

An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-9862

около 9 лет назад

An issue was discovered in phpMyAdmin. With a crafted login request it ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9861

около 9 лет назад

An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-9861

около 9 лет назад

An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-9861

около 9 лет назад

An issue was discovered in phpMyAdmin. Due to the limitation in URL ma ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9860

около 9 лет назад

An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbitraryServer']=true. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2016-9860

около 9 лет назад

An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbitraryServer']=true. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-9866

An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
0%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-9866

An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
0%
Низкий
около 9 лет назад
debian логотип
CVE-2016-9866

An issue was discovered in phpMyAdmin. When the arg_separator is diffe ...

CVSS3: 9.8
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-9865

An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-9865

An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
1%
Низкий
около 9 лет назад
debian логотип
CVE-2016-9865

An issue was discovered in phpMyAdmin. Due to a bug in serialized stri ...

CVSS3: 9.8
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-9864

An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 7.5
0%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-9864

An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tables of the configuration storage database, and if the control user has the necessary privileges, read access to some tables of the MySQL database. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 7.5
0%
Низкий
около 9 лет назад
debian логотип
CVE-2016-9864

An issue was discovered in phpMyAdmin. With a crafted username or a ta ...

CVSS3: 7.5
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-9863

An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) attack. All 4.6.x versions (prior to 4.6.5) are affected.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-9863

An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) attack. All 4.6.x versions (prior to 4.6.5) are affected.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
debian логотип
CVE-2016-9863

An issue was discovered in phpMyAdmin. With a very large request to ta ...

CVSS3: 7.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-9862

An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.

CVSS3: 7.5
0%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-9862

An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.

CVSS3: 7.5
0%
Низкий
около 9 лет назад
debian логотип
CVE-2016-9862

An issue was discovered in phpMyAdmin. With a crafted login request it ...

CVSS3: 7.5
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-9861

An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 7.5
0%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-9861

An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 7.5
0%
Низкий
около 9 лет назад
debian логотип
CVE-2016-9861

An issue was discovered in phpMyAdmin. Due to the limitation in URL ma ...

CVSS3: 7.5
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-9860

An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbitraryServer']=true. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 5.9
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-9860

An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbitraryServer']=true. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 5.9
1%
Низкий
около 9 лет назад

Уязвимостей на страницу