CVE-2016-5739
- EPSS 0.92%
- Veröffentlicht 03.07.2016 01:59:25
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, which makes it easier for remote attackers to condu...
CVE-2016-5734
- EPSS 72.92%
- Veröffentlicht 03.07.2016 01:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a craf...
CVE-2016-5733
- EPSS 1.24%
- Veröffentlicht 03.07.2016 01:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted table name that ...
CVE-2016-5732
- EPSS 0.22%
- Veröffentlicht 03.07.2016 01:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in the partition-range implementation in templates/table/structure/display_partitions.phtml in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allow remote attackers to inject arbitrary we...
CVE-2016-5731
- EPSS 0.42%
- Veröffentlicht 03.07.2016 01:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in examples/openid.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving an OpenID error m...
CVE-2016-5730
- EPSS 1.32%
- Veröffentlicht 03.07.2016 01:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to obtain sensitive information via vectors involving (1) an array value to FormDisplay.php, (2) incorrect data to validate.php, (3) unexpected d...
CVE-2016-5706
- EPSS 2.78%
- Veröffentlicht 03.07.2016 01:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to cause a denial of service via a large array in the scripts parameter.
CVE-2016-5705
- EPSS 0.61%
- Veröffentlicht 03.07.2016 01:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) server-privileges certificate data fields on the us...
CVE-2016-5704
- EPSS 0.28%
- Veröffentlicht 03.07.2016 01:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving a comment.
CVE-2016-5703
- EPSS 1.58%
- Veröffentlicht 03.07.2016 01:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column q...