Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

nvd логотип

CVE-2010-3055

почти 15 лет назад

The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2010-3055

почти 15 лет назад

The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2 ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-2958

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to a PHP backtrace and error messages (aka debugging messages), a different vulnerability than CVE-2010-3056.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2958

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to a PHP backtrace and error messages (aka debugging messages), a different vulnerability than CVE-2010-3056.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-2958

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in libraries/Error.class.php ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2009-4605

больше 15 лет назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2009-4605

больше 15 лет назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-4605

больше 15 лет назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-4605

больше 15 лет назад

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2 ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-3697

почти 16 лет назад

SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-3697

почти 16 лет назад

SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-3697

почти 16 лет назад

SQL injection vulnerability in the PDF schema generator functionality ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2009-3696

почти 16 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-3696

почти 16 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-3696

почти 16 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2009-2284

около 16 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-2284

около 16 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-2284

около 16 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2009-1285

больше 16 лет назад

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-1285

больше 16 лет назад

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2010-3055

The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-3055

The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2 ...

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-2958

Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to a PHP backtrace and error messages (aka debugging messages), a different vulnerability than CVE-2010-3056.

CVSS2: 4.3
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-2958

Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to a PHP backtrace and error messages (aka debugging messages), a different vulnerability than CVE-2010-3056.

CVSS2: 4.3
0%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-2958

Cross-site scripting (XSS) vulnerability in libraries/Error.class.php ...

CVSS2: 4.3
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2009-4605

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS2: 5
0%
Низкий
больше 15 лет назад
redhat логотип
CVE-2009-4605

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS2: 4.3
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4605

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

CVSS2: 5
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4605

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2 ...

CVSS2: 5
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-3697

SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.

CVSS2: 7.5
3%
Низкий
почти 16 лет назад
nvd логотип
CVE-2009-3697

SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.

CVSS2: 7.5
3%
Низкий
почти 16 лет назад
debian логотип
CVE-2009-3697

SQL injection vulnerability in the PDF schema generator functionality ...

CVSS2: 7.5
3%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2009-3696

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table.

CVSS2: 4.3
3%
Низкий
почти 16 лет назад
nvd логотип
CVE-2009-3696

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table.

CVSS2: 4.3
3%
Низкий
почти 16 лет назад
debian логотип
CVE-2009-3696

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2 ...

CVSS2: 4.3
3%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2009-2284

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.

CVSS2: 4.3
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-2284

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.

CVSS2: 4.3
1%
Низкий
около 16 лет назад
debian логотип
CVE-2009-2284

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 ...

CVSS2: 4.3
1%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2009-1285

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

CVSS2: 7.5
1%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-1285

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

CVSS2: 7.5
1%
Низкий
больше 16 лет назад

Уязвимостей на страницу