Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

debian логотип

CVE-2011-0987

больше 14 лет назад

The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAd ...

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2011-0986

больше 14 лет назад

phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly handle the absence of the (1) README, (2) ChangeLog, and (3) LICENSE files, which allows remote attackers to obtain the installation path via a direct request for a nonexistent file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-0986

больше 14 лет назад

phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly handle the absence of the (1) README, (2) ChangeLog, and (3) LICENSE files, which allows remote attackers to obtain the installation path via a direct request for a nonexistent file.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-0986

больше 14 лет назад

phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-4481

больше 14 лет назад

phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-4481

больше 14 лет назад

phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-4481

больше 14 лет назад

phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authen ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-4480

больше 14 лет назад

error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4480

больше 14 лет назад

error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-4480

больше 14 лет назад

error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-4329

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in libraries/common.lib.php in the database (db) search script in phpMyAdmin 2.11.x before 2.11.11.1 and 3.x before 3.3.8.1 allows remote attackers to inject arbitrary web script or HTML via a crafted request.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4329

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in libraries/common.lib.php in the database (db) search script in phpMyAdmin 2.11.x before 2.11.11.1 and 3.x before 3.3.8.1 allows remote attackers to inject arbitrary web script or HTML via a crafted request.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-4329

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton funct ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-3263

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-3263

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-3263

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-3056

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-3056

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-3056

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-3055

почти 15 лет назад

The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2011-0987

The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAd ...

CVSS2: 6.5
3%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-0986

phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly handle the absence of the (1) README, (2) ChangeLog, and (3) LICENSE files, which allows remote attackers to obtain the installation path via a direct request for a nonexistent file.

CVSS2: 5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-0986

phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly handle the absence of the (1) README, (2) ChangeLog, and (3) LICENSE files, which allows remote attackers to obtain the installation path via a direct request for a nonexistent file.

CVSS2: 5
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-0986

phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not ...

CVSS2: 5
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-4481

phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function.

CVSS2: 5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-4481

phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function.

CVSS2: 5
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4481

phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authen ...

CVSS2: 5
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-4480

error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".

CVSS2: 4.3
8%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-4480

error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".

CVSS2: 4.3
8%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4480

error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1 ...

CVSS2: 4.3
8%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-4329

Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in libraries/common.lib.php in the database (db) search script in phpMyAdmin 2.11.x before 2.11.11.1 and 3.x before 3.3.8.1 allows remote attackers to inject arbitrary web script or HTML via a crafted request.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-4329

Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in libraries/common.lib.php in the database (db) search script in phpMyAdmin 2.11.x before 2.11.11.1 and 3.x before 3.3.8.1 allows remote attackers to inject arbitrary web script or HTML via a crafted request.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4329

Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton funct ...

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-3263

Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name.

CVSS2: 4.3
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-3263

Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name.

CVSS2: 4.3
0%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-3263

Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php ...

CVSS2: 4.3
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-3056

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php.

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-3056

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php.

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-3056

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11 ...

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-3055

The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад

Уязвимостей на страницу