- EPSS 0.6%
- Veröffentlicht 26.03.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable)...
CVE-2009-1149
- EPSS 0.72%
- Veröffentlicht 26.03.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) c_type and possibly (...
CVE-2009-1150
- EPSS 0.75%
- Veröffentlicht 26.03.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in the export page (display_export.lib.php) in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allow remote attackers to inject arbitrary web script or HTML via the pma_db_filename_template...
CVE-2009-1151
- EPSS 93.03%
- Veröffentlicht 26.03.2009 14:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.
- EPSS 0.48%
- Veröffentlicht 17.12.2008 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table ...
CVE-2008-4775
- EPSS 7.23%
- Veröffentlicht 28.10.2008 19:46:09
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db paramet...
CVE-2008-4326
- EPSS 0.43%
- Veröffentlicht 30.09.2008 16:13:50
- Zuletzt bearbeitet 09.04.2025 00:30:58
The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte in...
CVE-2008-4096
- EPSS 12.62%
- Veröffentlicht 18.09.2008 15:04:27
- Zuletzt bearbeitet 09.04.2025 00:30:58
libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_func...
CVE-2008-3456
- EPSS 1.71%
- Veröffentlicht 04.08.2008 19:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.
CVE-2008-3457
- EPSS 0.59%
- Veröffentlicht 04.08.2008 19:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios i...