Search

Found 25 results in 184ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-1000018 high 7.5 7.5 FIX debian debian phpmyadmin 9y ago phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name
CVE-2017-1000017 high 8.8 8.8 FIX debian debian phpmyadmin 9y ago phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server
CVE-2017-1000016 high 7.5 7.5 FIX debian debian phpmyadmin 9y ago A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.
CVE-2017-1000014 high 7.5 7.5 FIX debian debian phpmyadmin 9y ago phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality
CVE-2016-6621 high 8.6 8.6 FIX debian debian phpmyadmin 10y ago The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
CVE-2016-9864 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the contro…
CVE-2016-9863 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago phpMyAdmin DoS Vulnerability
CVE-2016-9862 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.
CVE-2016-9861 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago phpMyAdmin Bypass white-list protection for URL redirection
CVE-2016-6633 high 8.1 8.1 FIX debian debian phpmyadmin 10y ago phpMyAdmin Remote code execution vulnerability when PHP is running with dbase extension
CVE-2016-6631 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a use…
CVE-2016-6619 high 8.8 8.8 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4…
CVE-2016-6617 high 8.1 8.1 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6…
CVE-2016-6616 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.…
CVE-2016-6611 high 8.1 8.1 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6…
CVE-2016-6609 high 8.8 8.8 FIX debian debian phpmyadmin 10y ago phpMyAdmin PHP code injection
CVE-2016-6606 high 8.1 8.1 FIX debian debian phpmyadmin 10y ago An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has access to a user's bro…
CVE-2016-5739 high 7.5 7.5 FIX suse susedebian debian phpmyadmin 10y ago The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, …
CVE-2016-5706 high 7.5 7.5 FIX suse susedebian debian phpmyadmin 10y ago js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to cause a denial of service via a large array in the scripts paramet…
CVE-2016-2041 high 7.5 7.5 FIX suse susefedora fedoradebian debian phpmyadmin 10y ago libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier fo…
CVE-2016-1927 high 7.5 7.5 FIX debian debian phpmyadmin 10y ago The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easie…
CVE-2012-5469 high 8.5 EXP phpmyadminwordpress 14y ago The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a direct request to wp-content/plugins/portable-php…
CVE-2012-5159 high 8.5 EXPFIX debian debian phpmyadmin 14y ago phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allo…
CVE-2011-2506 high 8.5 EXPFIX debian debian phpmyadmin 15y ago phpMyAdmin vulnerable to static code injection
CVE-2010-3055 high 7.5 FIX debian debian phpmyadmin 16y ago The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrar…