CVE-2018-7260
- EPSS 0.3%
- Published 21.02.2018 15:29:00
- Last modified 21.11.2024 04:11:53
Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVE-2017-1000499
- EPSS 11.44%
- Published 03.01.2018 14:29:00
- Last modified 21.11.2024 03:04:52
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.
CVE-2017-1000013
- EPSS 0.24%
- Published 17.07.2017 13:18:16
- Last modified 20.04.2025 01:37:25
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness
CVE-2017-1000014
- EPSS 1.14%
- Published 17.07.2017 13:18:16
- Last modified 20.04.2025 01:37:25
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality
CVE-2017-1000015
- EPSS 0.56%
- Published 17.07.2017 13:18:16
- Last modified 20.04.2025 01:37:25
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters
CVE-2017-1000016
- EPSS 0.49%
- Published 17.07.2017 13:18:16
- Last modified 20.04.2025 01:37:25
A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.
CVE-2017-1000017
- EPSS 0.92%
- Published 17.07.2017 13:18:16
- Last modified 20.04.2025 01:37:25
phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server
CVE-2017-1000018
- EPSS 1.3%
- Published 17.07.2017 13:18:16
- Last modified 20.04.2025 01:37:25
phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name
CVE-2016-6621
- EPSS 0.39%
- Published 31.01.2017 19:59:00
- Last modified 20.04.2025 01:37:25
The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
CVE-2016-9866
- EPSS 0.24%
- Published 11.12.2016 03:00:08
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (pr...