Количество 1 093
Количество 1 093
GHSA-vqv2-j98p-2cvh
phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to phpmyadmin.css.php, which reveals the installation path in an error message.
GHSA-vqcm-r62w-w437
phpMyAdmin remote variable manipulation
GHSA-vp7p-rxfv-rwm2
phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files.
GHSA-vf9x-fp9j-gp8c
Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php.
GHSA-vcwc-6mr9-8m7c
Cross-site Scripting in phpmyadmin
GHSA-vcvq-3f23-fr47
Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string.
GHSA-v7gh-wpgm-xx4r
An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
GHSA-v74x-h8vc-p3j5
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.
GHSA-v6fw-xf2c-8q43
phpMyAdmin Open Redirect in redirector
GHSA-v6fp-h79x-9rqc
phpMyAdmin CSRF vulnerability allowing arbitrary SQL execution
GHSA-v6fh-vg22-r6cm
phpMyAdmin ReCaptcha bypass
GHSA-v24v-vp5m-fpcr
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normalization.php or (2) js/normalization.js in the database normalization page, (3) templates/database/structure/sortable_header.phtml in the database structure page, or (4) the pos parameter to db_central_columns.php in the central columns page.
GHSA-rv6m-chvv-wmxg
phpMyAdmin Denial of service (DOS) attack in transformation feature
GHSA-rv57-479x-x4qv
phpMyAdmin Code Injection vulnerability
GHSA-rpvm-cpgc-m3w7
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database, (2) table, or (3) column name that is improperly handled during rendering of the table browse page; a crafted ENUM value that is improperly handled during rendering of the (4) table print view or (5) zoom search page; or (6) a crafted pma_fontsize cookie that is improperly handled during rendering of the home page.
GHSA-rmmf-5xhh-gg27
phpMyAdmin path disclosure
GHSA-rm5v-f378-qgp9
libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION superglobal array.
GHSA-rh74-5835-jpxp
phpMyAdmin vulnerable to Cross-site Scripting
GHSA-rfpg-2fp8-2fph
phpMyAdmin multiple cross-site scripting vulnerabilities
GHSA-r7cq-qp4v-9qxv
error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-vqv2-j98p-2cvh phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to phpmyadmin.css.php, which reveals the installation path in an error message. | 1% Низкий | около 3 лет назад | ||
GHSA-vqcm-r62w-w437 phpMyAdmin remote variable manipulation | 25% Средний | около 3 лет назад | ||
GHSA-vp7p-rxfv-rwm2 phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files. | 0% Низкий | около 3 лет назад | ||
GHSA-vf9x-fp9j-gp8c Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php. | 0% Низкий | около 3 лет назад | ||
GHSA-vcwc-6mr9-8m7c Cross-site Scripting in phpmyadmin | CVSS3: 6.1 | 67% Средний | больше 3 лет назад | |
GHSA-vcvq-3f23-fr47 Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string. | 11% Средний | больше 3 лет назад | ||
GHSA-v7gh-wpgm-xx4r An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected. | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-v74x-h8vc-p3j5 Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/. | 1% Низкий | больше 3 лет назад | ||
GHSA-v6fw-xf2c-8q43 phpMyAdmin Open Redirect in redirector | 0% Низкий | около 3 лет назад | ||
GHSA-v6fp-h79x-9rqc phpMyAdmin CSRF vulnerability allowing arbitrary SQL execution | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
GHSA-v6fh-vg22-r6cm phpMyAdmin ReCaptcha bypass | 1% Низкий | около 3 лет назад | ||
GHSA-v24v-vp5m-fpcr Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normalization.php or (2) js/normalization.js in the database normalization page, (3) templates/database/structure/sortable_header.phtml in the database structure page, or (4) the pos parameter to db_central_columns.php in the central columns page. | CVSS3: 5.4 | 0% Низкий | около 3 лет назад | |
GHSA-rv6m-chvv-wmxg phpMyAdmin Denial of service (DOS) attack in transformation feature | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
GHSA-rv57-479x-x4qv phpMyAdmin Code Injection vulnerability | CVSS3: 9.8 | 73% Высокий | около 3 лет назад | |
GHSA-rpvm-cpgc-m3w7 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database, (2) table, or (3) column name that is improperly handled during rendering of the table browse page; a crafted ENUM value that is improperly handled during rendering of the (4) table print view or (5) zoom search page; or (6) a crafted pma_fontsize cookie that is improperly handled during rendering of the home page. | 1% Низкий | около 3 лет назад | ||
GHSA-rmmf-5xhh-gg27 phpMyAdmin path disclosure | CVSS3: 5.3 | 1% Низкий | около 3 лет назад | |
GHSA-rm5v-f378-qgp9 libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION superglobal array. | 4% Низкий | около 3 лет назад | ||
GHSA-rh74-5835-jpxp phpMyAdmin vulnerable to Cross-site Scripting | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-rfpg-2fp8-2fph phpMyAdmin multiple cross-site scripting vulnerabilities | 0% Низкий | около 3 лет назад | ||
GHSA-r7cq-qp4v-9qxv error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]". | 7% Низкий | около 3 лет назад |
Уязвимостей на страницу