Vulnerability index

Browse CVEs

156 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

phpMyAdmin MEDIUM 5.3
CVE-2016-9859

An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9858

An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in saved searches…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 6.1
CVE-2016-9857

An issue was discovered in phpMyAdmin. XSS is possible because of a weakness in a regular expression used in some JavaScript processing. All 4.6.x ve…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 6.1
CVE-2016-9856

An XSS issue was discovered in phpMyAdmin because of an improper fix for CVE-2016-2559 in PMASA-2016-10. This issue is resolved by using a copy of a …

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9855

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9854

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9853

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9852

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9851

An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior …

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9850

An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the ru…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin CRITICAL 9.8
CVE-2016-9849

An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username …

Patch available
Fix from $2,300 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9848

An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9847

An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpMyAdmin generates one at runti…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin HIGH 8.1
CVE-2016-6633

An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remote code execution attack against certain PHP installations that are ru…

Patch available
Fix from $1,950 2016-12-11
phpMyAdmin MEDIUM 5.9
CVE-2016-6632

An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmin may not delete temporary files during the import of ESRI files. All…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin HIGH 7.5
CVE-2016-6631

An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI appli…

Patch available
Fix from $1,950 2016-12-11
phpMyAdmin MEDIUM 6.5
CVE-2016-6630

An issue was discovered in phpMyAdmin. An authenticated user can trigger a denial-of-service (DoS) attack by entering a very long password at the cha…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin CRITICAL 9.8
CVE-2016-6629

An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie val…

Patch available
Fix from $2,300 2016-12-11
phpMyAdmin MEDIUM 6.3
CVE-2016-6628

An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicious SVG file. All 4.6.x versio…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-6627

An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to …

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.4
CVE-2016-6626

An issue was discovered in phpMyAdmin. An attacker could redirect a user to a malicious web page. All 4.6.x versions (prior to 4.6.4), 4.4.x versions…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.9
CVE-2016-6624

An issue was discovered in phpMyAdmin involving improper enforcement of the IP-based authentication rules. When phpMyAdmin is used with IPv6 in a pro…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 6.5
CVE-2016-6623

An issue was discovered in phpMyAdmin. An authorized user can cause a denial-of-service (DoS) attack on a server by passing large values to a loop. A…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.9
CVE-2016-6622

An issue was discovered in phpMyAdmin. An unauthenticated user is able to execute a denial-of-service (DoS) attack by forcing persistent connections …

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin CRITICAL 9.8
CVE-2016-6620

An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. Th…

Patch available
Fix from $2,300 2016-12-11
phpMyAdmin HIGH 8.8
CVE-2016-6619

An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection attack against the account of th…

Patch available
Fix from $1,950 2016-12-11
phpMyAdmin MEDIUM 6.5
CVE-2016-6618

An issue was discovered in phpMyAdmin. The transformation feature allows a user to trigger a denial-of-service (DoS) attack against the server. All 4…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin HIGH 8.1
CVE-2016-6617

An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the expo…

Patch available
Fix from $1,950 2016-12-11
phpMyAdmin HIGH 7.5
CVE-2016-6616

An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of…

Patch available
Fix from $1,950 2016-12-11
phpMyAdmin MEDIUM 6.1
CVE-2016-6615

XSS issues were discovered in phpMyAdmin. This affects navigation pane and database/table hiding feature (a specially-crafted database name can be us…

Patch available
Fix from $1,600 2016-12-11