Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

debian логотип

CVE-2008-7251

больше 15 лет назад

libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a ...

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2008-5621

больше 16 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2008-5621

больше 16 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2008-5621

больше 16 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x b ...

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2008-4775

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2008-4775

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

EPSS: Низкий
nvd логотип

CVE-2008-4775

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2008-4775

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2008-4096

почти 17 лет назад

libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.

CVSS2: 8.5
EPSS: Средний
nvd логотип

CVE-2008-4096

почти 17 лет назад

libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.

CVSS2: 8.5
EPSS: Средний
debian логотип

CVE-2008-4096

почти 17 лет назад

libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 all ...

CVSS2: 8.5
EPSS: Средний
ubuntu логотип

CVE-2008-3457

около 17 лет назад

Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2008-3457

около 17 лет назад

Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2008-3457

около 17 лет назад

Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin be ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2008-3456

около 17 лет назад

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2008-3456

около 17 лет назад

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2008-3456

около 17 лет назад

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2008-3197

около 17 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2008-3197

около 17 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2008-3197

около 17 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2 ...

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2008-7251

libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a ...

CVSS2: 10
2%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2008-5621

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

CVSS2: 6
0%
Низкий
больше 16 лет назад
nvd логотип
CVE-2008-5621

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

CVSS2: 6
0%
Низкий
больше 16 лет назад
debian логотип
CVE-2008-5621

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x b ...

CVSS2: 6
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2008-4775

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

CVSS2: 2.6
7%
Низкий
почти 17 лет назад
redhat логотип
CVE-2008-4775

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

7%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-4775

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

CVSS2: 2.6
7%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-4775

Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin ...

CVSS2: 2.6
7%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-4096

libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.

CVSS2: 8.5
13%
Средний
почти 17 лет назад
nvd логотип
CVE-2008-4096

libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.

CVSS2: 8.5
13%
Средний
почти 17 лет назад
debian логотип
CVE-2008-4096

libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 all ...

CVSS2: 8.5
13%
Средний
почти 17 лет назад
ubuntu логотип
CVE-2008-3457

Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.

CVSS2: 2.6
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-3457

Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.

CVSS2: 2.6
1%
Низкий
около 17 лет назад
debian логотип
CVE-2008-3457

Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin be ...

CVSS2: 2.6
1%
Низкий
около 17 лет назад
ubuntu логотип
CVE-2008-3456

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.

CVSS2: 6.4
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-3456

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.

CVSS2: 6.4
2%
Низкий
около 17 лет назад
debian логотип
CVE-2008-3456

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from ...

CVSS2: 6.4
2%
Низкий
около 17 лет назад
ubuntu логотип
CVE-2008-3197

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.

CVSS2: 3.5
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-3197

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.

CVSS2: 3.5
0%
Низкий
около 17 лет назад
debian логотип
CVE-2008-3197

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2 ...

CVSS2: 3.5
0%
Низкий
около 17 лет назад

Уязвимостей на страницу