CVE-2016-9865
- EPSS 0.66%
- Veröffentlicht 11.12.2016 03:00:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x v...
CVE-2016-9864
- EPSS 0.44%
- Veröffentlicht 11.12.2016 03:00:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. With a crafted username or a table name, it was possible to inject SQL statements in the tracking functionality that would run with the privileges of the control user. This gives read and write access to the tab...
CVE-2016-9863
- EPSS 0.61%
- Veröffentlicht 11.12.2016 03:00:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) attack. All 4.6.x versions (prior to 4.6.5) are affected.
CVE-2016-9862
- EPSS 0.46%
- Veröffentlicht 11.12.2016 03:00:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.
CVE-2016-9861
- EPSS 0.25%
- Veröffentlicht 11.12.2016 03:00:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) ar...
CVE-2016-9860
- EPSS 1.02%
- Veröffentlicht 11.12.2016 03:00:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbitraryServer']=true. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0....
CVE-2016-9859
- EPSS 0.64%
- Veröffentlicht 11.12.2016 02:59:59
- Zuletzt bearbeitet 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior ...
CVE-2016-9858
- EPSS 0.64%
- Veröffentlicht 11.12.2016 02:59:57
- Zuletzt bearbeitet 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in saved searches feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions...
CVE-2016-9857
- EPSS 0.42%
- Veröffentlicht 11.12.2016 02:59:56
- Zuletzt bearbeitet 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. XSS is possible because of a weakness in a regular expression used in some JavaScript processing. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) ...
CVE-2016-9856
- EPSS 0.42%
- Veröffentlicht 11.12.2016 02:59:55
- Zuletzt bearbeitet 12.04.2025 10:46:40
An XSS issue was discovered in phpMyAdmin because of an improper fix for CVE-2016-2559 in PMASA-2016-10. This issue is resolved by using a copy of a hash to avoid a race condition. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15....