Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 095

Количество 1 095

nvd логотип

CVE-2010-3055

больше 15 лет назад

The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2010-3055

больше 15 лет назад

The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2 ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-2958

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to a PHP backtrace and error messages (aka debugging messages), a different vulnerability than CVE-2010-3056.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2958

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to a PHP backtrace and error messages (aka debugging messages), a different vulnerability than CVE-2010-3056.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-2958

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in libraries/Error.class.php ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2009-4605

около 16 лет назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2009-4605

около 16 лет назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-4605

около 16 лет назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-4605

около 16 лет назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2 ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-3697

больше 16 лет назад

SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-3697

больше 16 лет назад

SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-3697

больше 16 лет назад

SQL injection vulnerability in the PDF schema generator functionality ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2009-3696

больше 16 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-3696

больше 16 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-3696

больше 16 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2009-2284

больше 16 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-2284

больше 16 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-2284

больше 16 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2009-1285

почти 17 лет назад

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-1285

почти 17 лет назад

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2010-3055

The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.

CVSS2: 7.5
2%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-3055

The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2 ...

CVSS2: 7.5
2%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2010-2958

Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to a PHP backtrace and error messages (aka debugging messages), a different vulnerability than CVE-2010-3056.

CVSS2: 4.3
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-2958

Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to a PHP backtrace and error messages (aka debugging messages), a different vulnerability than CVE-2010-3056.

CVSS2: 4.3
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-2958

Cross-site scripting (XSS) vulnerability in libraries/Error.class.php ...

CVSS2: 4.3
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-4605

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS2: 5
0%
Низкий
около 16 лет назад
redhat логотип
CVE-2009-4605

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS2: 4.3
0%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-4605

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS2: 5
0%
Низкий
около 16 лет назад
debian логотип
CVE-2009-4605

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2 ...

CVSS2: 5
0%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2009-3697

SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.

CVSS2: 7.5
3%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-3697

SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.

CVSS2: 7.5
3%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3697

SQL injection vulnerability in the PDF schema generator functionality ...

CVSS2: 7.5
3%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-3696

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table.

CVSS2: 4.3
3%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-3696

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table.

CVSS2: 4.3
3%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3696

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2 ...

CVSS2: 4.3
3%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-2284

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.

CVSS2: 4.3
1%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-2284

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.

CVSS2: 4.3
1%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-2284

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 ...

CVSS2: 4.3
1%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1285

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

CVSS2: 7.5
1%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-1285

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

CVSS2: 7.5
1%
Низкий
почти 17 лет назад

Уязвимостей на страницу