Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

debian логотип

CVE-2012-1190

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the replication-setup func ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4782

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in libraries/config/ConfigFile.class.php in the setup interface in phpMyAdmin 3.4.x before 3.4.9 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4782

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in libraries/config/ConfigFile.class.php in the setup interface in phpMyAdmin 3.4.x before 3.4.9 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-4782

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in libraries/config/ConfigFil ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4780

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) table sections.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4780

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) table sections.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-4780

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in libraries/displ ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4634

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rename panel; (3) a crafted SQL query, related to the table overview panel; (4) a crafted SQL query, related to the view creation dialog; (5) a crafted column type, related to the table search dialog; or (6) a crafted column type, related to the create index dialog.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4634

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rename panel; (3) a crafted SQL query, related to the table overview panel; (4) a crafted SQL query, related to the view creation dialog; (5) a crafted column type, related to the table search dialog; or (6) a crafted column type, related to the create index dialog.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-4634

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4. ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4107

больше 13 лет назад

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2011-4107

больше 13 лет назад

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2011-4107

больше 13 лет назад

The simplexml_load_string function in the XML import plug-in (librarie ...

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2011-4064

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4064

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-4064

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in the setup interface in php ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-3646

больше 13 лет назад

phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to phpmyadmin.css.php, which reveals the installation path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-3646

больше 13 лет назад

phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to phpmyadmin.css.php, which reveals the installation path in an error message.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-3646

больше 13 лет назад

phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote atta ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-3592

больше 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the PMA_unInlineEditRow function in js/sql.js in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a (1) database name, (2) table name, or (3) column name that is not properly handled after an inline-editing operation.

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2012-1190

Cross-site scripting (XSS) vulnerability in the replication-setup func ...

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4782

Cross-site scripting (XSS) vulnerability in libraries/config/ConfigFile.class.php in the setup interface in phpMyAdmin 3.4.x before 3.4.9 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4782

Cross-site scripting (XSS) vulnerability in libraries/config/ConfigFile.class.php in the setup interface in phpMyAdmin 3.4.x before 3.4.9 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4782

Cross-site scripting (XSS) vulnerability in libraries/config/ConfigFil ...

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4780

Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) table sections.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4780

Multiple cross-site scripting (XSS) vulnerabilities in libraries/display_export.lib.php in phpMyAdmin 3.4.x before 3.4.9 allow remote attackers to inject arbitrary web script or HTML via crafted URL parameters, related to the export panels in the (1) server, (2) database, and (3) table sections.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4780

Multiple cross-site scripting (XSS) vulnerabilities in libraries/displ ...

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4634

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rename panel; (3) a crafted SQL query, related to the table overview panel; (4) a crafted SQL query, related to the view creation dialog; (5) a crafted column type, related to the table search dialog; or (6) a crafted column type, related to the create index dialog.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4634

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4.x before 3.4.8 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted database name, related to the Database Synchronize panel; (2) a crafted database name, related to the Database rename panel; (3) a crafted SQL query, related to the table overview panel; (4) a crafted SQL query, related to the view creation dialog; (5) a crafted column type, related to the table search dialog; or (6) a crafted column type, related to the create index dialog.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4634

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.4. ...

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4107

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

CVSS3: 6.5
12%
Средний
больше 13 лет назад
nvd логотип
CVE-2011-4107

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

CVSS3: 6.5
12%
Средний
больше 13 лет назад
debian логотип
CVE-2011-4107

The simplexml_load_string function in the XML import plug-in (librarie ...

CVSS3: 6.5
12%
Средний
больше 13 лет назад
ubuntu логотип
CVE-2011-4064

Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.

CVSS2: 4.3
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2011-4064

Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.

CVSS2: 4.3
1%
Низкий
почти 14 лет назад
debian логотип
CVE-2011-4064

Cross-site scripting (XSS) vulnerability in the setup interface in php ...

CVSS2: 4.3
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2011-3646

phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to phpmyadmin.css.php, which reveals the installation path in an error message.

CVSS2: 5
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-3646

phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to phpmyadmin.css.php, which reveals the installation path in an error message.

CVSS2: 5
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-3646

phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote atta ...

CVSS2: 5
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-3592

Multiple cross-site scripting (XSS) vulnerabilities in the PMA_unInlineEditRow function in js/sql.js in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a (1) database name, (2) table name, or (3) column name that is not properly handled after an inline-editing operation.

CVSS2: 3.5
0%
Низкий
больше 10 лет назад

Уязвимостей на страницу