Логотип exploitDog
product: "phpmyadmin"
Консоль
Логотип exploitDog

exploitDog

product: "phpmyadmin"

Количество 1 093

Количество 1 093

nvd логотип

CVE-2006-6943

больше 18 лет назад

PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/darkblue_orange/layout.inc.php; and via the (1) lang[], (2) target[], (3) db[], (4) goto[], (5) table[], and (6) tbl_group[] array arguments to (c) index.php, and the (7) back[] argument to (d) sql.php; and an invalid (8) sort_by parameter to (e) server_databases.php and (9) db parameter to (f) db_printview.php.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2006-6943

больше 18 лет назад

PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full s ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2006-6942

больше 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2006-6942

больше 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2006-6942

больше 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin befo ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2006-6374

больше 18 лет назад

Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a phpMyAdmin cookie in (1) css/phpmyadmin.css.php, (2) db_create.php, (3) index.php, (4) left.php, (5) libraries/session.inc.php, (6) libraries/transformations/overview.php, (7) querywindow.php, (8) server_engines.php, and possibly other files.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-6374

больше 18 лет назад

Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a phpMyAdmin cookie in (1) css/phpmyadmin.css.php, (2) db_create.php, (3) index.php, (4) left.php, (5) libraries/session.inc.php, (6) libraries/transformations/overview.php, (7) querywindow.php, (8) server_engines.php, and possibly other files.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2006-6374

больше 18 лет назад

Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2006-6373

больше 18 лет назад

PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-6373

больше 18 лет назад

PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the path in an error message.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2006-6373

больше 18 лет назад

PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive infor ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-5718

почти 19 лет назад

Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web script or HTML via UTF-7 or US-ASCII encoded characters, which are injected into an error message, as demonstrated by a request with a utf7 charset parameter accompanied by UTF-7 data.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-5718

почти 19 лет назад

Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web script or HTML via UTF-7 or US-ASCII encoded characters, which are injected into an error message, as demonstrated by a request with a utf7 charset parameter accompanied by UTF-7 data.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-5718

почти 19 лет назад

Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2. ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2006-5117

почти 19 лет назад

phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-5117

почти 19 лет назад

phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2006-5117

почти 19 лет назад

phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web do ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-5116

почти 19 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdmin before 2.9.1-rc1 allow remote attackers to perform unauthorized actions as another user by (1) directly setting a token in the URL though dynamic variable evaluation and (2) unsetting arbitrary variables via the _REQUEST array, related to (a) libraries/common.lib.php, (b) session.inc.php, and (c) url_generating.lib.php. NOTE: the PHP unset function vector is covered by CVE-2006-3017.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2006-5116

почти 19 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdmin before 2.9.1-rc1 allow remote attackers to perform unauthorized actions as another user by (1) directly setting a token in the URL though dynamic variable evaluation and (2) unsetting arbitrary variables via the _REQUEST array, related to (a) libraries/common.lib.php, (b) session.inc.php, and (c) url_generating.lib.php. NOTE: the PHP unset function vector is covered by CVE-2006-3017.

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2006-5116

почти 19 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdm ...

CVSS2: 5.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2006-6943

PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/darkblue_orange/layout.inc.php; and via the (1) lang[], (2) target[], (3) db[], (4) goto[], (5) table[], and (6) tbl_group[] array arguments to (c) index.php, and the (7) back[] argument to (d) sql.php; and an invalid (8) sort_by parameter to (e) server_databases.php and (9) db parameter to (f) db_printview.php.

CVSS2: 5
11%
Средний
больше 18 лет назад
debian логотип
CVE-2006-6943

PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full s ...

CVSS2: 5
11%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2006-6942

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.

CVSS2: 6.8
2%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-6942

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the newname parameter to db_operations.php, the (4) query_history_latest, (5) query_history_latest_db, and (6) querydisplay_tab parameters to (c) querywindow.php, and (7) the pos parameter to (d) sql.php.

CVSS2: 6.8
2%
Низкий
больше 18 лет назад
debian логотип
CVE-2006-6942

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin befo ...

CVSS2: 6.8
2%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-6374

Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a phpMyAdmin cookie in (1) css/phpmyadmin.css.php, (2) db_create.php, (3) index.php, (4) left.php, (5) libraries/session.inc.php, (6) libraries/transformations/overview.php, (7) querywindow.php, (8) server_engines.php, and possibly other files.

CVSS2: 7.5
1%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-6374

Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a phpMyAdmin cookie in (1) css/phpmyadmin.css.php, (2) db_create.php, (3) index.php, (4) left.php, (5) libraries/session.inc.php, (6) libraries/transformations/overview.php, (7) querywindow.php, (8) server_engines.php, and possibly other files.

CVSS2: 7.5
1%
Низкий
больше 18 лет назад
debian логотип
CVE-2006-6374

Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow ...

CVSS2: 7.5
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-6373

PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the path in an error message.

CVSS2: 5
0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-6373

PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the path in an error message.

CVSS2: 5
0%
Низкий
больше 18 лет назад
debian логотип
CVE-2006-6373

PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive infor ...

CVSS2: 5
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-5718

Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web script or HTML via UTF-7 or US-ASCII encoded characters, which are injected into an error message, as demonstrated by a request with a utf7 charset parameter accompanied by UTF-7 data.

CVSS2: 4.3
1%
Низкий
почти 19 лет назад
nvd логотип
CVE-2006-5718

Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web script or HTML via UTF-7 or US-ASCII encoded characters, which are injected into an error message, as demonstrated by a request with a utf7 charset parameter accompanied by UTF-7 data.

CVSS2: 4.3
1%
Низкий
почти 19 лет назад
debian логотип
CVE-2006-5718

Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2. ...

CVSS2: 4.3
1%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2006-5117

phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files.

CVSS2: 5
0%
Низкий
почти 19 лет назад
nvd логотип
CVE-2006-5117

phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files.

CVSS2: 5
0%
Низкий
почти 19 лет назад
debian логотип
CVE-2006-5117

phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web do ...

CVSS2: 5
0%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2006-5116

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdmin before 2.9.1-rc1 allow remote attackers to perform unauthorized actions as another user by (1) directly setting a token in the URL though dynamic variable evaluation and (2) unsetting arbitrary variables via the _REQUEST array, related to (a) libraries/common.lib.php, (b) session.inc.php, and (c) url_generating.lib.php. NOTE: the PHP unset function vector is covered by CVE-2006-3017.

CVSS2: 5.1
3%
Низкий
почти 19 лет назад
nvd логотип
CVE-2006-5116

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdmin before 2.9.1-rc1 allow remote attackers to perform unauthorized actions as another user by (1) directly setting a token in the URL though dynamic variable evaluation and (2) unsetting arbitrary variables via the _REQUEST array, related to (a) libraries/common.lib.php, (b) session.inc.php, and (c) url_generating.lib.php. NOTE: the PHP unset function vector is covered by CVE-2006-3017.

CVSS2: 5.1
3%
Низкий
почти 19 лет назад
debian логотип
CVE-2006-5116

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdm ...

CVSS2: 5.1
3%
Низкий
почти 19 лет назад

Уязвимостей на страницу