Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

ubuntu логотип

CVE-2016-5099

около 9 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-5099

около 9 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-5099

около 9 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4. ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-5098

около 9 лет назад

Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-5098

около 9 лет назад

Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-5098

около 9 лет назад

Directory traversal vulnerability in libraries/error_report.lib.php in ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2016-5097

около 9 лет назад

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-5097

около 9 лет назад

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-5097

около 9 лет назад

phpMyAdmin before 4.6.2 places tokens in query strings and does not ar ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2016-4412

больше 8 лет назад

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2016-4412

больше 8 лет назад

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2016-4412

больше 8 лет назад

An issue was discovered in phpMyAdmin. A user can be tricked into foll ...

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2016-2562

больше 9 лет назад

The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2016-2562

больше 9 лет назад

The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2016-2562

больше 9 лет назад

The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5 ...

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2016-2561

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normalization.php or (2) js/normalization.js in the database normalization page, (3) templates/database/structure/sortable_header.phtml in the database structure page, or (4) the pos parameter to db_central_columns.php in the central columns page.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2016-2561

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normalization.php or (2) js/normalization.js in the database normalization page, (3) templates/database/structure/sortable_header.phtml in the database structure page, or (4) the pos parameter to db_central_columns.php in the central columns page.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2016-2561

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4. ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2016-2560

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Host HTTP header, related to libraries/Config.class.php; (2) crafted JSON data, related to file_echo.php; (3) a crafted SQL query, related to js/functions.js; (4) the initial parameter to libraries/server_privileges.lib.php in the user accounts page; or (5) the it parameter to libraries/controllers/TableSearchController.class.php in the zoom search page.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-2560

больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Host HTTP header, related to libraries/Config.class.php; (2) crafted JSON data, related to file_echo.php; (3) a crafted SQL query, related to js/functions.js; (4) the initial parameter to libraries/server_privileges.lib.php in the user accounts page; or (5) the it parameter to libraries/controllers/TableSearchController.class.php in the zoom search page.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-5099

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.

CVSS3: 6.1
0%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-5099

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.

CVSS3: 6.1
0%
Низкий
около 9 лет назад
debian логотип
CVE-2016-5099

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4. ...

CVSS3: 6.1
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-5098

Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.

CVSS3: 5.3
0%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-5098

Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.

CVSS3: 5.3
0%
Низкий
около 9 лет назад
debian логотип
CVE-2016-5098

Directory traversal vulnerability in libraries/error_report.lib.php in ...

CVSS3: 5.3
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-5097

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.

CVSS3: 5.3
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-5097

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.

CVSS3: 5.3
1%
Низкий
около 9 лет назад
debian логотип
CVE-2016-5097

phpMyAdmin before 4.6.2 places tokens in query strings and does not ar ...

CVSS3: 5.3
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-4412

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

CVSS3: 4.4
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2016-4412

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

CVSS3: 4.4
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2016-4412

An issue was discovered in phpMyAdmin. A user can be tricked into foll ...

CVSS3: 4.4
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2016-2562

The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.

CVSS3: 6.8
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2562

The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.

CVSS3: 6.8
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2562

The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5 ...

CVSS3: 6.8
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-2561

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normalization.php or (2) js/normalization.js in the database normalization page, (3) templates/database/structure/sortable_header.phtml in the database structure page, or (4) the pos parameter to db_central_columns.php in the central columns page.

CVSS3: 5.4
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2561

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normalization.php or (2) js/normalization.js in the database normalization page, (3) templates/database/structure/sortable_header.phtml in the database structure page, or (4) the pos parameter to db_central_columns.php in the central columns page.

CVSS3: 5.4
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2561

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4. ...

CVSS3: 5.4
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-2560

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Host HTTP header, related to libraries/Config.class.php; (2) crafted JSON data, related to file_echo.php; (3) a crafted SQL query, related to js/functions.js; (4) the initial parameter to libraries/server_privileges.lib.php in the user accounts page; or (5) the it parameter to libraries/controllers/TableSearchController.class.php in the zoom search page.

CVSS3: 6.1
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2560

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Host HTTP header, related to libraries/Config.class.php; (2) crafted JSON data, related to file_echo.php; (3) a crafted SQL query, related to js/functions.js; (4) the initial parameter to libraries/server_privileges.lib.php in the user accounts page; or (5) the it parameter to libraries/controllers/TableSearchController.class.php in the zoom search page.

CVSS3: 6.1
1%
Низкий
больше 9 лет назад

Уязвимостей на страницу