CVE-2016-6611
- EPSS 0.37%
- Published 11.12.2016 02:59:17
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x ...
CVE-2016-6610
- EPSS 0.45%
- Published 11.12.2016 02:59:15
- Last modified 12.04.2025 10:46:40
A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4...
CVE-2016-6609
- EPSS 0.43%
- Published 11.12.2016 02:59:14
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior ...
CVE-2016-6608
- EPSS 0.45%
- Published 11.12.2016 02:59:12
- Last modified 12.04.2025 10:46:40
XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the XSS attack. All 4.6.x versions (prior to 4.6.4) are affected.
CVE-2016-6607
- EPSS 0.54%
- Published 11.12.2016 02:59:11
- Last modified 12.04.2025 10:46:40
XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS editor (certain fields in the graphical GIS editor are not properly escaped and can be used to trigger an ...
CVE-2016-6606
- EPSS 0.26%
- Published 11.12.2016 02:59:10
- Last modified 12.04.2025 10:46:40
An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has access to a user's browser cookie file to decrypt the username and passwo...
CVE-2016-4412
- EPSS 0.24%
- Published 11.12.2016 02:59:09
- Last modified 12.04.2025 10:46:40
An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (p...
CVE-2016-5099
- EPSS 0.49%
- Published 05.07.2016 01:59:07
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.
CVE-2016-5098
- EPSS 0.45%
- Published 05.07.2016 01:59:06
- Last modified 12.04.2025 10:46:40
Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.
CVE-2016-5097
- EPSS 0.55%
- Published 05.07.2016 01:59:05
- Last modified 12.04.2025 10:46:40
phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.