Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 095

Количество 1 095

debian логотип

CVE-2015-6830

больше 10 лет назад

libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4. ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2015-3903

больше 10 лет назад

libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-3903

больше 10 лет назад

libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-3903

больше 10 лет назад

libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-3902

больше 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-3902

больше 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-3902

больше 10 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the setu ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-2206

почти 11 лет назад

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2015-2206

почти 11 лет назад

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-2206

почти 11 лет назад

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2 ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-9219

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-9219

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-9219

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the redirection feature in ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9218

около 11 лет назад

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2014-9218

около 11 лет назад

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2014-9218

около 11 лет назад

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x be ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2014-8961

около 11 лет назад

Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-8961

около 11 лет назад

Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-8961

около 11 лет назад

Directory traversal vulnerability in libraries/error_report.lib.php in ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-8960

около 11 лет назад

Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename.

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2015-6830

libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4. ...

CVSS2: 5
21%
Средний
больше 10 лет назад
ubuntu логотип
CVE-2015-3903

libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS2: 4.3
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3903

libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS2: 4.3
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3903

libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x ...

CVSS2: 4.3
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-3902

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

CVSS2: 6.8
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3902

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

CVSS2: 6.8
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3902

Multiple cross-site request forgery (CSRF) vulnerabilities in the setu ...

CVSS2: 6.8
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-2206

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

CVSS2: 5
1%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-2206

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

CVSS2: 5
1%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-2206

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2 ...

CVSS2: 5
1%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2014-9219

Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-9219

Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-9219

Cross-site scripting (XSS) vulnerability in the redirection feature in ...

CVSS2: 4.3
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-9218

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.

CVSS2: 5
17%
Средний
около 11 лет назад
nvd логотип
CVE-2014-9218

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.

CVSS2: 5
17%
Средний
около 11 лет назад
debian логотип
CVE-2014-9218

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x be ...

CVSS2: 5
17%
Средний
около 11 лет назад
ubuntu логотип
CVE-2014-8961

Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter.

CVSS2: 4
2%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-8961

Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter.

CVSS2: 4
2%
Низкий
около 11 лет назад
debian логотип
CVE-2014-8961

Directory traversal vulnerability in libraries/error_report.lib.php in ...

CVSS2: 4
2%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-8960

Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename.

CVSS2: 3.5
0%
Низкий
около 11 лет назад

Уязвимостей на страницу