CVE-2024-5413
- EPSS 0.24%
- Veröffentlicht 28.05.2024 13:15:11
- Zuletzt bearbeitet 10.10.2025 19:54:02
A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/scheduled.php, all parameters. This vulnerabilities could allow an attacker to create a specially crafted...
CVE-2024-5414
- EPSS 0.24%
- Veröffentlicht 28.05.2024 13:15:11
- Zuletzt bearbeitet 10.10.2025 19:53:31
A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/get_file.php, 'view' parameter. This vulnerabilities could allow an attacker to create a specially crafte...
CVE-2024-5415
- EPSS 0.24%
- Veröffentlicht 28.05.2024 13:15:11
- Zuletzt bearbeitet 10.10.2025 19:45:36
A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/backup.php, 'comments' and 'db' parameters. This vulnerabilities could allow an attacker to create a spec...
CVE-2015-3637
- EPSS 0.85%
- Veröffentlicht 28.12.2017 02:29:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute arbitrary SQL commands via the username and password parameters.
CVE-2015-4180
- EPSS 1.04%
- Veröffentlicht 25.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is unknown; the details are obtain...
CVE-2015-4181
- EPSS 18.37%
- Veröffentlicht 25.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is unknown; the details are obtain...
CVE-2015-3638
- EPSS 1.61%
- Veröffentlicht 21.07.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
phpMyBackupPro before 2.5 does not validate integer input, which allows remote authenticated users to execute arbitrary PHP code by injecting scripts via the path, filename, and period parameters to scheduled.php, and making requests to injected scri...
CVE-2015-3639
- EPSS 1.37%
- Veröffentlicht 21.07.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
phpMyBackupPro 2.5 and earlier does not properly sanitize input strings, which allows remote authenticated users to execute arbitrary PHP code by storing a crafted string in a user configuration file.
CVE-2015-3640
- EPSS 0.88%
- Veröffentlicht 21.07.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowledge of a web-accessible and web-writeable directory on the target system to inject and execute arbitra...
- EPSS 1.89%
- Veröffentlicht 23.11.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter. NOTE: the provenance of this information is unknown; the details are obt...