Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

github логотип

GHSA-r6w3-53hv-rjhw

около 3 лет назад

An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-r643-7xfg-ppc5

около 3 лет назад

phpMyAdmin allows to detect if user is logged in

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-r57r-r9wp-wc2v

около 3 лет назад

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-r43q-435x-vmw7

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.

EPSS: Низкий
github логотип

GHSA-r43p-59cr-4g96

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin 2.8.0.3, 2.8.0.2, 2.8.1-dev, and 2.9.0-dev allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

EPSS: Низкий
github логотип

GHSA-r3pq-mp8v-cp33

около 3 лет назад

phpMyAdmin Multiple Cross-site Scripting Vulnerabilities in the Database Structure page

EPSS: Низкий
github логотип

GHSA-r326-mp8g-6xfc

около 3 лет назад

phpMyAdmin Bypass white-list protection for URL redirection

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-r2vw-p77f-vc27

около 3 лет назад

phpMyAdmin Bypass logout timeout

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-r2gg-p76x-g7qv

больше 3 лет назад

phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in tbl_rename.php.

EPSS: Низкий
github логотип

GHSA-r2fq-59w2-3vq4

около 3 лет назад

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the curl wrapper issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-r2cc-3v4v-j29x

больше 3 лет назад

The register_globals emulation in phpMyAdmin 2.7.0 rc1 allows remote attackers to exploit other vulnerabilities in phpMyAdmin by modifying the import_blacklist variable in grab_globals.php, which can then be used to overwrite other variables.

EPSS: Низкий
github логотип

GHSA-qrm4-w2r7-479c

около 3 лет назад

XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS editor (certain fields in the graphical GIS editor are not properly escaped and can be used to trigger an XSS attack); Relation view; the following Transformations: Formatted, Imagelink, JPEG: Upload, RegexValidation, JPEG inline, PNG inline, and transformation wrapper; XML export; MediaWiki export; Designer; When the MySQL server is running with a specially-crafted log_bin directive; Database tab; Replication feature; and Database search. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-qqgf-6922-rxxc

больше 3 лет назад

Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.

EPSS: Средний
github логотип

GHSA-qjm2-f85j-5793

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/sql.js; (2) ENUM editor page, related to js/functions.js; (3) monitor page, related to js/server_status_monitor.js; (4) query charts page, related to js/tbl_chart.js; or (5) table relations page, related to libraries/tbl_relation.lib.php.

EPSS: Низкий
github логотип

GHSA-qgrq-64g6-mmh6

около 3 лет назад

phpMyAdmin DoS Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-qf3f-7x69-qfv3

около 3 лет назад

phpMyAdmin DoS Vulnerability

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-qc6p-fjq3-q3x8

около 3 лет назад

A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-qc2g-2jgq-733p

около 3 лет назад

An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-q8p5-hgjr-4chh

больше 3 лет назад

phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.

EPSS: Низкий
github логотип

GHSA-q7v2-w38r-pv7v

около 3 лет назад

phpMyAdmin Multiple XSS Vulnerabilities

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-r6w3-53hv-rjhw

An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-r643-7xfg-ppc5

phpMyAdmin allows to detect if user is logged in

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-r57r-r9wp-wc2v

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

CVSS3: 4.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-r43q-435x-vmw7

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.

0%
Низкий
около 3 лет назад
github логотип
GHSA-r43p-59cr-4g96

Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin 2.8.0.3, 2.8.0.2, 2.8.1-dev, and 2.9.0-dev allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-r3pq-mp8v-cp33

phpMyAdmin Multiple Cross-site Scripting Vulnerabilities in the Database Structure page

0%
Низкий
около 3 лет назад
github логотип
GHSA-r326-mp8g-6xfc

phpMyAdmin Bypass white-list protection for URL redirection

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-r2vw-p77f-vc27

phpMyAdmin Bypass logout timeout

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-r2gg-p76x-g7qv

phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in tbl_rename.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-r2fq-59w2-3vq4

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the curl wrapper issue.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-r2cc-3v4v-j29x

The register_globals emulation in phpMyAdmin 2.7.0 rc1 allows remote attackers to exploit other vulnerabilities in phpMyAdmin by modifying the import_blacklist variable in grab_globals.php, which can then be used to overwrite other variables.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-qrm4-w2r7-479c

XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS editor (certain fields in the graphical GIS editor are not properly escaped and can be used to trigger an XSS attack); Relation view; the following Transformations: Formatted, Imagelink, JPEG: Upload, RegexValidation, JPEG inline, PNG inline, and transformation wrapper; XML export; MediaWiki export; Designer; When the MySQL server is running with a specially-crafted log_bin directive; Database tab; Replication feature; and Database search. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-qqgf-6922-rxxc

Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.

14%
Средний
больше 3 лет назад
github логотип
GHSA-qjm2-f85j-5793

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/sql.js; (2) ENUM editor page, related to js/functions.js; (3) monitor page, related to js/server_status_monitor.js; (4) query charts page, related to js/tbl_chart.js; or (5) table relations page, related to libraries/tbl_relation.lib.php.

0%
Низкий
около 3 лет назад
github логотип
GHSA-qgrq-64g6-mmh6

phpMyAdmin DoS Vulnerability

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-qf3f-7x69-qfv3

phpMyAdmin DoS Vulnerability

CVSS3: 5.9
1%
Низкий
около 3 лет назад
github логотип
GHSA-qc6p-fjq3-q3x8

A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-qc2g-2jgq-733p

An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-q8p5-hgjr-4chh

phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-q7v2-w38r-pv7v

phpMyAdmin Multiple XSS Vulnerabilities

0%
Низкий
около 3 лет назад

Уязвимостей на страницу