CVE-2016-0724
- EPSS 0.58%
- Veröffentlicht 22.02.2016 05:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhid...
CVE-2016-2045
- EPSS 0.28%
- Veröffentlicht 20.02.2016 01:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a SQL query that triggers JSON data in a response.
CVE-2016-2044
- EPSS 0.44%
- Veröffentlicht 20.02.2016 01:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
CVE-2016-2043
- EPSS 0.39%
- Veröffentlicht 20.02.2016 01:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the ...
CVE-2016-2042
- EPSS 0.58%
- Veröffentlicht 20.02.2016 01:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path ...
CVE-2016-2041
- EPSS 1.03%
- Veröffentlicht 20.02.2016 01:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restri...
CVE-2016-2040
- EPSS 0.49%
- Veröffentlicht 20.02.2016 01:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) s...
CVE-2016-2039
- EPSS 0.38%
- Veröffentlicht 20.02.2016 01:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.
CVE-2016-2038
- EPSS 1.2%
- Veröffentlicht 20.02.2016 01:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
CVE-2016-2270
- EPSS 0.3%
- Veröffentlicht 19.02.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.