Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

github логотип

GHSA-vqv2-j98p-2cvh

около 3 лет назад

phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to phpmyadmin.css.php, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-vqcm-r62w-w437

около 3 лет назад

phpMyAdmin remote variable manipulation

EPSS: Средний
github логотип

GHSA-vp7p-rxfv-rwm2

около 3 лет назад

phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files.

EPSS: Низкий
github логотип

GHSA-vf9x-fp9j-gp8c

около 3 лет назад

Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php.

EPSS: Низкий
github логотип

GHSA-vcwc-6mr9-8m7c

больше 3 лет назад

Cross-site Scripting in phpmyadmin

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-vcvq-3f23-fr47

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string.

EPSS: Средний
github логотип

GHSA-v7gh-wpgm-xx4r

около 3 лет назад

An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-v74x-h8vc-p3j5

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.

EPSS: Низкий
github логотип

GHSA-v6fw-xf2c-8q43

около 3 лет назад

phpMyAdmin Open Redirect in redirector

EPSS: Низкий
github логотип

GHSA-v6fp-h79x-9rqc

около 3 лет назад

phpMyAdmin CSRF vulnerability allowing arbitrary SQL execution

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-v6fh-vg22-r6cm

около 3 лет назад

phpMyAdmin ReCaptcha bypass

EPSS: Низкий
github логотип

GHSA-v24v-vp5m-fpcr

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normalization.php or (2) js/normalization.js in the database normalization page, (3) templates/database/structure/sortable_header.phtml in the database structure page, or (4) the pos parameter to db_central_columns.php in the central columns page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-rv6m-chvv-wmxg

около 3 лет назад

phpMyAdmin Denial of service (DOS) attack in transformation feature

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-rv57-479x-x4qv

около 3 лет назад

phpMyAdmin Code Injection vulnerability

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-rpvm-cpgc-m3w7

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database, (2) table, or (3) column name that is improperly handled during rendering of the table browse page; a crafted ENUM value that is improperly handled during rendering of the (4) table print view or (5) zoom search page; or (6) a crafted pma_fontsize cookie that is improperly handled during rendering of the home page.

EPSS: Низкий
github логотип

GHSA-rmmf-5xhh-gg27

около 3 лет назад

phpMyAdmin path disclosure

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-rm5v-f378-qgp9

около 3 лет назад

libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION superglobal array.

EPSS: Низкий
github логотип

GHSA-rh74-5835-jpxp

около 3 лет назад

phpMyAdmin vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-rfpg-2fp8-2fph

около 3 лет назад

phpMyAdmin multiple cross-site scripting vulnerabilities

EPSS: Низкий
github логотип

GHSA-r7cq-qp4v-9qxv

около 3 лет назад

error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-vqv2-j98p-2cvh

phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to phpmyadmin.css.php, which reveals the installation path in an error message.

1%
Низкий
около 3 лет назад
github логотип
GHSA-vqcm-r62w-w437

phpMyAdmin remote variable manipulation

25%
Средний
около 3 лет назад
github логотип
GHSA-vp7p-rxfv-rwm2

phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files.

0%
Низкий
около 3 лет назад
github логотип
GHSA-vf9x-fp9j-gp8c

Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php.

0%
Низкий
около 3 лет назад
github логотип
GHSA-vcwc-6mr9-8m7c

Cross-site Scripting in phpmyadmin

CVSS3: 6.1
67%
Средний
больше 3 лет назад
github логотип
GHSA-vcvq-3f23-fr47

Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string.

11%
Средний
больше 3 лет назад
github логотип
GHSA-v7gh-wpgm-xx4r

An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-v74x-h8vc-p3j5

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-v6fw-xf2c-8q43

phpMyAdmin Open Redirect in redirector

0%
Низкий
около 3 лет назад
github логотип
GHSA-v6fp-h79x-9rqc

phpMyAdmin CSRF vulnerability allowing arbitrary SQL execution

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-v6fh-vg22-r6cm

phpMyAdmin ReCaptcha bypass

1%
Низкий
около 3 лет назад
github логотип
GHSA-v24v-vp5m-fpcr

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normalization.php or (2) js/normalization.js in the database normalization page, (3) templates/database/structure/sortable_header.phtml in the database structure page, or (4) the pos parameter to db_central_columns.php in the central columns page.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-rv6m-chvv-wmxg

phpMyAdmin Denial of service (DOS) attack in transformation feature

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-rv57-479x-x4qv

phpMyAdmin Code Injection vulnerability

CVSS3: 9.8
73%
Высокий
около 3 лет назад
github логотип
GHSA-rpvm-cpgc-m3w7

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database, (2) table, or (3) column name that is improperly handled during rendering of the table browse page; a crafted ENUM value that is improperly handled during rendering of the (4) table print view or (5) zoom search page; or (6) a crafted pma_fontsize cookie that is improperly handled during rendering of the home page.

1%
Низкий
около 3 лет назад
github логотип
GHSA-rmmf-5xhh-gg27

phpMyAdmin path disclosure

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-rm5v-f378-qgp9

libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION superglobal array.

4%
Низкий
около 3 лет назад
github логотип
GHSA-rh74-5835-jpxp

phpMyAdmin vulnerable to Cross-site Scripting

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-rfpg-2fp8-2fph

phpMyAdmin multiple cross-site scripting vulnerabilities

0%
Низкий
около 3 лет назад
github логотип
GHSA-r7cq-qp4v-9qxv

error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".

7%
Низкий
около 3 лет назад

Уязвимостей на страницу