- EPSS 11.17%
- Published 14.07.2011 23:55:05
- Last modified 11.04.2025 00:51:21
Directory traversal vulnerability in libraries/display_tbl.lib.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1, when a certain MIME transformation feature is enabled, allows remote authenticated users to include and execute arbitrary l...
CVE-2011-2505
- EPSS 24.58%
- Published 14.07.2011 23:55:04
- Last modified 11.04.2025 00:51:21
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify t...
CVE-2011-2506
- EPSS 21.88%
- Published 14.07.2011 23:55:04
- Last modified 11.04.2025 00:51:21
setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging...
CVE-2011-2507
- EPSS 3.74%
- Published 14.07.2011 23:55:04
- Last modified 11.04.2025 00:51:21
libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLAC...
CVE-2011-0987
- EPSS 2.7%
- Published 14.02.2011 22:00:06
- Last modified 11.04.2025 00:51:21
The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's e...
- EPSS 0.55%
- Published 14.02.2011 22:00:00
- Last modified 11.04.2025 00:51:21
phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly handle the absence of the (1) README, (2) ChangeLog, and (3) LICENSE files, which allows remote attackers to obtain the installation path via a direct request for a nonex...
- EPSS 0.69%
- Published 17.12.2010 19:00:23
- Last modified 11.04.2025 00:51:21
phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function.
CVE-2010-4480
- EPSS 7.45%
- Published 08.12.2010 16:00:02
- Last modified 11.04.2025 00:51:21
error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".
CVE-2010-4329
- EPSS 0.61%
- Published 02.12.2010 16:22:21
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in libraries/common.lib.php in the database (db) search script in phpMyAdmin 2.11.x before 2.11.11.1 and 3.x before 3.3.8.1 allows remote attackers to inject arbitrary web scri...
CVE-2010-3263
- EPSS 0.39%
- Published 10.09.2010 20:00:01
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name.