CVE-2005-0653
- EPSS 0.16%
- Published 02.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
phpMyAdmin 2.6.1 does not properly grant permissions on tables with an underscore in the name, which grants remote authenticated users more privileges than intended.
CVE-2005-0992
- EPSS 10.16%
- Published 02.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter.
CVE-2004-1055
- EPSS 1.17%
- Published 01.03.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm ...
CVE-2005-0543
- EPSS 2.34%
- Published 24.02.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no pa...
- EPSS 4.57%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.
- EPSS 0.39%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.
CVE-2004-2630
- EPSS 2.09%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
CVE-2004-2631
- EPSS 14.2%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.
CVE-2004-2632
- EPSS 2.95%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables.
- EPSS 13.29%
- Published 03.03.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.