Phpmyadmin

Phpmyadmin

272 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.47%
  • Published 16.07.2008 18:41:00
  • Last modified 09.04.2025 00:30:58

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) th...

  • EPSS 0.68%
  • Published 02.07.2008 17:14:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libr...

  • EPSS 0.18%
  • Published 23.04.2008 16:05:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir v...

  • EPSS 0.04%
  • Published 31.03.2008 22:44:00
  • Last modified 09.04.2025 00:30:58

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

  • EPSS 0.76%
  • Published 04.03.2008 23:44:00
  • Last modified 09.04.2025 00:30:58

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by usin...

  • EPSS 0.5%
  • Published 23.11.2007 20:46:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in libraries/auth/cookie.auth.lib.php in phpMyAdmin before 2.11.2.2, when logins are authenticated with the cookie auth_type, allows remote attackers to inject arbitrary web script or HTML via the convcharset ...

  • EPSS 1.05%
  • Published 15.11.2007 00:46:00
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter.

  • EPSS 0.48%
  • Published 15.11.2007 00:46:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to inject arbitrary web script or HTML via a hex-encoded IMG element in the db parameter in a PO...

  • EPSS 10.79%
  • Published 19.10.2007 23:17:00
  • Last modified 09.04.2025 00:30:58

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.2 allow remote attackers to inject arbitrary web script or HTML via certain input available in (1) PHP_SELF in (a) server_status.php, and (b) grab_globals.lib.php, (c) di...

  • EPSS 10.79%
  • Published 12.10.2007 10:17:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string.