Search

Found 32 results in 185ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-1000018 high 7.5 7.5 FIX debian debian phpmyadmin 9y ago phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name
CVE-2017-1000017 high 8.8 8.8 FIX debian debian phpmyadmin 9y ago phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server
CVE-2017-1000016 high 7.5 7.5 FIX debian debian phpmyadmin 9y ago A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.
CVE-2017-1000014 high 7.5 7.5 FIX debian debian phpmyadmin 9y ago phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality
CVE-2016-6621 high 8.6 8.6 FIX debian debian phpmyadmin 10y ago The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
CVE-2016-9866 critical 9.8 9.8 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All …
CVE-2016-9865 critical 9.8 9.8 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.…
CVE-2016-9864 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the contro…
CVE-2016-9863 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago phpMyAdmin DoS Vulnerability
CVE-2016-9862 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.
CVE-2016-9861 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago phpMyAdmin Bypass white-list protection for URL redirection
CVE-2016-9849 critical 9.8 9.8 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x vers…
CVE-2016-6633 high 8.1 8.1 FIX debian debian phpmyadmin 10y ago phpMyAdmin Remote code execution vulnerability when PHP is running with dbase extension
CVE-2016-6631 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a use…
CVE-2016-6629 critical 9.8 9.8 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by A…
CVE-2016-6620 critical 9.8 9.8 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution bec…
CVE-2016-6619 high 8.8 8.8 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4…
CVE-2016-6617 high 8.1 8.1 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6…
CVE-2016-6616 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.…
CVE-2016-6611 high 8.1 8.1 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6…
CVE-2016-6609 high 8.8 8.8 FIX debian debian phpmyadmin 10y ago phpMyAdmin PHP code injection
CVE-2016-6606 high 8.1 8.1 FIX debian debian phpmyadmin 10y ago An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has access to a user's bro…
CVE-2016-5739 high 7.5 7.5 FIX suse susedebian debian phpmyadmin 10y ago The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, …
CVE-2016-5734 critical 9.8 10.0 EXPFIX debian debian phpmyadmin 10y ago phpMyAdmin Code Injection vulnerability
CVE-2016-5706 high 7.5 7.5 FIX suse susedebian debian phpmyadmin 10y ago js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to cause a denial of service via a large array in the scripts paramet…
CVE-2016-5703 critical 9.8 9.8 FIX suse susedebian debian phpmyadmin 10y ago SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted dat…
CVE-2016-2041 high 7.5 7.5 FIX suse susefedora fedoradebian debian phpmyadmin 10y ago libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier fo…
CVE-2016-1927 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easie…
CVE-2012-5469 high 8.5 EXP phpmyadminwordpress 14y ago The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a direct request to wp-content/plugins/portable-php…
CVE-2012-5159 high 8.5 EXPFIX debian debian phpmyadmin 14y ago phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allo…
CVE-2011-2506 high 8.5 EXPFIX debian debian phpmyadmin 15y ago phpMyAdmin vulnerable to static code injection
CVE-2010-3055 high 7.5 FIX debian debian phpmyadmin 16y ago The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrar…