Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

ubuntu логотип

CVE-2011-2508

около 14 лет назад

Directory traversal vulnerability in libraries/display_tbl.lib.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1, when a certain MIME transformation feature is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in a GLOBALS[mime_map][$meta->name][transformation] parameter.

CVSS2: 6
EPSS: Средний
nvd логотип

CVE-2011-2508

около 14 лет назад

Directory traversal vulnerability in libraries/display_tbl.lib.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1, when a certain MIME transformation feature is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in a GLOBALS[mime_map][$meta->name][transformation] parameter.

CVSS2: 6
EPSS: Средний
debian логотип

CVE-2011-2508

около 14 лет назад

Directory traversal vulnerability in libraries/display_tbl.lib.php in ...

CVSS2: 6
EPSS: Средний
ubuntu логотип

CVE-2011-2507

около 14 лет назад

libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION superglobal array.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2011-2507

около 14 лет назад

libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION superglobal array.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2011-2507

около 14 лет назад

libraries/server_synchronize.lib.php in the Synchronize implementation ...

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2011-2506

около 14 лет назад

setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2011-2506

около 14 лет назад

setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2011-2506

около 14 лет назад

setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2011-2505

около 14 лет назад

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

CVSS2: 6.4
EPSS: Средний
nvd логотип

CVE-2011-2505

около 14 лет назад

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

CVSS2: 6.4
EPSS: Средний
debian логотип

CVE-2011-2505

около 14 лет назад

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication ...

CVSS2: 6.4
EPSS: Средний
ubuntu логотип

CVE-2011-1941

больше 13 лет назад

Open redirect vulnerability in the redirector feature in phpMyAdmin 3.4.x before 3.4.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-1941

больше 13 лет назад

Open redirect vulnerability in the redirector feature in phpMyAdmin 3.4.x before 3.4.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-1941

больше 13 лет назад

Open redirect vulnerability in the redirector feature in phpMyAdmin 3. ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-1940

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.3.x before 3.3.10.1 and 3.4.x before 3.4.1 allow remote attackers to inject arbitrary web script or HTML via a crafted table name that triggers improper HTML rendering on a Tracking page, related to (1) libraries/tbl_links.inc.php and (2) tbl_tracking.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-1940

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.3.x before 3.3.10.1 and 3.4.x before 3.4.1 allow remote attackers to inject arbitrary web script or HTML via a crafted table name that triggers improper HTML rendering on a Tracking page, related to (1) libraries/tbl_links.inc.php and (2) tbl_tracking.php.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-1940

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.3. ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-0987

больше 14 лет назад

The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2011-0987

больше 14 лет назад

The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.

CVSS2: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-2508

Directory traversal vulnerability in libraries/display_tbl.lib.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1, when a certain MIME transformation feature is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in a GLOBALS[mime_map][$meta->name][transformation] parameter.

CVSS2: 6
11%
Средний
около 14 лет назад
nvd логотип
CVE-2011-2508

Directory traversal vulnerability in libraries/display_tbl.lib.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1, when a certain MIME transformation feature is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in a GLOBALS[mime_map][$meta->name][transformation] parameter.

CVSS2: 6
11%
Средний
около 14 лет назад
debian логотип
CVE-2011-2508

Directory traversal vulnerability in libraries/display_tbl.lib.php in ...

CVSS2: 6
11%
Средний
около 14 лет назад
ubuntu логотип
CVE-2011-2507

libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION superglobal array.

CVSS2: 6.5
4%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-2507

libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION superglobal array.

CVSS2: 6.5
4%
Низкий
около 14 лет назад
debian логотип
CVE-2011-2507

libraries/server_synchronize.lib.php in the Synchronize implementation ...

CVSS2: 6.5
4%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-2506

setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array.

CVSS2: 7.5
22%
Средний
около 14 лет назад
nvd логотип
CVE-2011-2506

setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array.

CVSS2: 7.5
22%
Средний
около 14 лет назад
debian логотип
CVE-2011-2506

setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 ...

CVSS2: 7.5
22%
Средний
около 14 лет назад
ubuntu логотип
CVE-2011-2505

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

CVSS2: 6.4
25%
Средний
около 14 лет назад
nvd логотип
CVE-2011-2505

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

CVSS2: 6.4
25%
Средний
около 14 лет назад
debian логотип
CVE-2011-2505

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication ...

CVSS2: 6.4
25%
Средний
около 14 лет назад
ubuntu логотип
CVE-2011-1941

Open redirect vulnerability in the redirector feature in phpMyAdmin 3.4.x before 3.4.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-1941

Open redirect vulnerability in the redirector feature in phpMyAdmin 3.4.x before 3.4.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-1941

Open redirect vulnerability in the redirector feature in phpMyAdmin 3. ...

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-1940

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.3.x before 3.3.10.1 and 3.4.x before 3.4.1 allow remote attackers to inject arbitrary web script or HTML via a crafted table name that triggers improper HTML rendering on a Tracking page, related to (1) libraries/tbl_links.inc.php and (2) tbl_tracking.php.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-1940

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.3.x before 3.3.10.1 and 3.4.x before 3.4.1 allow remote attackers to inject arbitrary web script or HTML via a crafted table name that triggers improper HTML rendering on a Tracking page, related to (1) libraries/tbl_links.inc.php and (2) tbl_tracking.php.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-1940

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.3. ...

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-0987

The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.

CVSS2: 6.5
3%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-0987

The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.

CVSS2: 6.5
3%
Низкий
больше 14 лет назад

Уязвимостей на страницу