CVE-2016-9855
- EPSS 0.72%
- Published 11.12.2016 02:59:53
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is ins...
CVE-2016-9854
- EPSS 0.5%
- Published 11.12.2016 02:59:52
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is ins...
CVE-2016-9853
- EPSS 0.85%
- Published 11.12.2016 02:59:51
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is ins...
CVE-2016-9852
- EPSS 0.5%
- Published 11.12.2016 02:59:50
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is ins...
CVE-2016-9851
- EPSS 0.24%
- Published 11.12.2016 02:59:49
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected.
CVE-2016-9850
- EPSS 0.57%
- Published 11.12.2016 02:59:48
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to ...
CVE-2016-9849
- EPSS 0.3%
- Published 11.12.2016 02:59:47
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4...
CVE-2016-9848
- EPSS 0.34%
- Published 11.12.2016 02:59:45
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
CVE-2016-9847
- EPSS 0.43%
- Published 11.12.2016 02:59:44
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpMyAdmin generates one at runtime. A vulnerability was reported where the way this value is created uses a weak algorithm. This coul...
CVE-2016-6633
- EPSS 1.83%
- Published 11.12.2016 02:59:43
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remote code execution attack against certain PHP installations that are running with the dbase extension. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15....