Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

nvd логотип

CVE-2008-3032

около 17 лет назад

Cross-site scripting (XSS) vulnerability in the phpMyAdmin (phpmyadmin) extension 3.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-2960

около 17 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2008-2960

около 17 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2008-2960

около 17 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2008-1924

больше 17 лет назад

Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variable.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2008-1924

больше 17 лет назад

Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variable.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2008-1924

больше 17 лет назад

Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2008-1567

больше 17 лет назад

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2008-1567

больше 17 лет назад

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2008-1567

больше 17 лет назад

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) passw ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2008-1149

больше 17 лет назад

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2008-1149

больше 17 лет назад

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

EPSS: Низкий
nvd логотип

CVE-2008-1149

больше 17 лет назад

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2008-1149

больше 17 лет назад

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters ...

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2007-6100

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in libraries/auth/cookie.auth.lib.php in phpMyAdmin before 2.11.2.2, when logins are authenticated with the cookie auth_type, allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter to index.php, a different vulnerability than CVE-2005-0992.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2007-6100

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in libraries/auth/cookie.auth.lib.php in phpMyAdmin before 2.11.2.2, when logins are authenticated with the cookie auth_type, allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter to index.php, a different vulnerability than CVE-2005-0992.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2007-6100

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in libraries/auth/cookie.auth ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2007-5977

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to inject arbitrary web script or HTML via a hex-encoded IMG element in the db parameter in a POST request, a different vulnerability than CVE-2006-6942.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2007-5977

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to inject arbitrary web script or HTML via a hex-encoded IMG element in the db parameter in a POST request, a different vulnerability than CVE-2006-6942.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2007-5977

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmi ...

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-3032

Cross-site scripting (XSS) vulnerability in the phpMyAdmin (phpmyadmin) extension 3.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
0%
Низкий
около 17 лет назад
ubuntu логотип
CVE-2008-2960

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.

CVSS2: 2.6
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-2960

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.

CVSS2: 2.6
1%
Низкий
около 17 лет назад
debian логотип
CVE-2008-2960

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, ...

CVSS2: 2.6
1%
Низкий
около 17 лет назад
ubuntu логотип
CVE-2008-1924

Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variable.

CVSS2: 3.5
0%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-1924

Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variable.

CVSS2: 3.5
0%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-1924

Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running ...

CVSS2: 3.5
0%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-1567

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

CVSS3: 5.5
0%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-1567

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

CVSS3: 5.5
0%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-1567

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) passw ...

CVSS3: 5.5
0%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-1149

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

CVSS2: 5.1
1%
Низкий
больше 17 лет назад
redhat логотип
CVE-2008-1149

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-1149

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

CVSS2: 5.1
1%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-1149

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters ...

CVSS2: 5.1
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2007-6100

Cross-site scripting (XSS) vulnerability in libraries/auth/cookie.auth.lib.php in phpMyAdmin before 2.11.2.2, when logins are authenticated with the cookie auth_type, allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter to index.php, a different vulnerability than CVE-2005-0992.

CVSS2: 2.6
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2007-6100

Cross-site scripting (XSS) vulnerability in libraries/auth/cookie.auth.lib.php in phpMyAdmin before 2.11.2.2, when logins are authenticated with the cookie auth_type, allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter to index.php, a different vulnerability than CVE-2005-0992.

CVSS2: 2.6
1%
Низкий
больше 17 лет назад
debian логотип
CVE-2007-6100

Cross-site scripting (XSS) vulnerability in libraries/auth/cookie.auth ...

CVSS2: 2.6
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2007-5977

Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to inject arbitrary web script or HTML via a hex-encoded IMG element in the db parameter in a POST request, a different vulnerability than CVE-2006-6942.

CVSS2: 3.5
0%
Низкий
больше 17 лет назад
nvd логотип
CVE-2007-5977

Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to inject arbitrary web script or HTML via a hex-encoded IMG element in the db parameter in a POST request, a different vulnerability than CVE-2006-6942.

CVSS2: 3.5
0%
Низкий
больше 17 лет назад
debian логотип
CVE-2007-5977

Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmi ...

CVSS2: 3.5
0%
Низкий
больше 17 лет назад

Уязвимостей на страницу