Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

redhat логотип

CVE-2014-4348

около 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-4348

около 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2014-4348

около 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2. ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2014-1879

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin before 4.1.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename in an import action.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2014-1879

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin before 4.1.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename in an import action.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2014-1879

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin b ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2013-5029

почти 12 лет назад

phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-5029

почти 12 лет назад

phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-5029

почти 12 лет назад

phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to byp ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-5003

около 12 лет назад

Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2013-5003

около 12 лет назад

Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2013-5003

около 12 лет назад

Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5. ...

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2013-5002

около 12 лет назад

Cross-site scripting (XSS) vulnerability in libraries/schema/Export_Relation_Schema.class.php in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted pageNumber value to schema_export.php.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2013-5002

около 12 лет назад

Cross-site scripting (XSS) vulnerability in libraries/schema/Export_Relation_Schema.class.php in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted pageNumber value to schema_export.php.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2013-5002

около 12 лет назад

Cross-site scripting (XSS) vulnerability in libraries/schema/Export_Re ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2013-5001

около 12 лет назад

Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2013-5001

около 12 лет назад

Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2013-5001

около 12 лет назад

Cross-site scripting (XSS) vulnerability in libraries/plugins/transfor ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2013-5000

около 12 лет назад

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-5000

около 12 лет назад

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2014-4348

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-4348

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.

CVSS2: 3.5
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-4348

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2. ...

CVSS2: 3.5
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-1879

Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin before 4.1.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename in an import action.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-1879

Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin before 4.1.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename in an import action.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-1879

Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin b ...

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-5029

phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.

CVSS2: 4.3
2%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-5029

phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.

CVSS2: 4.3
2%
Низкий
почти 12 лет назад
debian логотип
CVE-2013-5029

phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to byp ...

CVSS2: 4.3
2%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2013-5003

Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php.

CVSS2: 6.5
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-5003

Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php.

CVSS2: 6.5
0%
Низкий
около 12 лет назад
debian логотип
CVE-2013-5003

Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5. ...

CVSS2: 6.5
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2013-5002

Cross-site scripting (XSS) vulnerability in libraries/schema/Export_Relation_Schema.class.php in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted pageNumber value to schema_export.php.

CVSS2: 3.5
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-5002

Cross-site scripting (XSS) vulnerability in libraries/schema/Export_Relation_Schema.class.php in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted pageNumber value to schema_export.php.

CVSS2: 3.5
0%
Низкий
около 12 лет назад
debian логотип
CVE-2013-5002

Cross-site scripting (XSS) vulnerability in libraries/schema/Export_Re ...

CVSS2: 3.5
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2013-5001

Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.

CVSS2: 3.5
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-5001

Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted object name associated with a TextLinkTransformationPlugin link.

CVSS2: 3.5
0%
Низкий
около 12 лет назад
debian логотип
CVE-2013-5001

Cross-site scripting (XSS) vulnerability in libraries/plugins/transfor ...

CVSS2: 3.5
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2013-5000

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.

CVSS2: 5
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-5000

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.

CVSS2: 5
0%
Низкий
около 12 лет назад

Уязвимостей на страницу