Vulnerability index

Browse CVEs

156 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

phpMyAdmin MEDIUM 6.8
CVE-2016-6614

An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username su…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-6613

An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is …

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 6.5
CVE-2016-6612

An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. A…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin HIGH 8.1
CVE-2016-6611

An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the expo…

Patch available
Fix from $1,950 2016-12-11
phpMyAdmin HIGH 8.8
CVE-2016-6609

An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature…

Patch available
Fix from $1,950 2016-12-11
phpMyAdmin MEDIUM 6.1
CVE-2016-6608

XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted da…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 6.1
CVE-2016-6607

XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS edito…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin HIGH 8.1
CVE-2016-6606

An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This ca…

Patch available
Fix from $1,950 2016-12-11
phpMyAdmin MEDIUM 6.1
CVE-2016-5099

Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web s…

Patch available
Fix from $1,600 2016-07-05
phpMyAdmin MEDIUM 5.3
CVE-2016-5098

Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the ex…

Patch available
Fix from $1,600 2016-07-05
phpMyAdmin CRITICAL 9.8
CVE-2016-5734EPSS 81%

phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_repla…

Patch available
Fix from $2,300 2016-07-03
phpMyAdmin MEDIUM 6.1
CVE-2016-5733

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allow remote …

Patch available
Fix from $1,600 2016-07-03
phpMyAdmin MEDIUM 6.1
CVE-2016-5732

Multiple cross-site scripting (XSS) vulnerabilities in the partition-range implementation in templates/table/structure/display_partitions.phtml in th…

Patch available
Fix from $1,600 2016-07-03
phpMyAdmin MEDIUM 6.1
CVE-2016-5731

Cross-site scripting (XSS) vulnerability in examples/openid.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 a…

Patch available
Fix from $1,600 2016-07-03
phpMyAdmin MEDIUM 5.3
CVE-2016-5730

phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to obtain sensitive information via vectors …

Patch available
Fix from $1,600 2016-07-03
phpMyAdmin HIGH 7.5
CVE-2016-5706

js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to cause a denial o…

Patch available
Fix from $1,950 2016-07-03
phpMyAdmin MEDIUM 6.1
CVE-2016-5704

Cross-site scripting (XSS) vulnerability in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web…

Patch available
Fix from $1,600 2016-07-03
phpMyAdmin MEDIUM 6.1
CVE-2016-5701

setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to condu…

Patch available
Fix from $1,600 2016-07-03
phpMyAdmin MEDIUM 6.8
CVE-2016-2562

The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL se…

Patch available
Fix from $1,600 2016-03-01
phpMyAdmin MEDIUM 5.4
CVE-2016-2561

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to …

Patch available
Fix from $1,600 2016-03-01
phpMyAdmin MEDIUM 6.1
CVE-2016-2560

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remot…

Patch available
Fix from $1,600 2016-03-01
phpMyAdmin MEDIUM 5.4
CVE-2016-2559

Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL parser in phpMyAdmin 4.5.x bef…

Patch available
Fix from $1,600 2016-03-01
phpMyAdmin HIGH 7.5
CVE-2016-1927

The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Mat…

Patch available
Fix from $1,950 2016-02-20
phpMyAdmin MEDIUM 5.3
CVE-2015-8669

libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to ob…

Patch available
Fix from $1,600 2015-12-26
phpMyAdmin MEDIUM 5.0
CVE-2015-7873

The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url pa…

Patch available
Fix from $1,600 2015-10-28
phpMyAdmin MEDIUM 5.0
CVE-2015-6830EPSS 10%

libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass…

Patch available
Fix from $1,600 2015-09-14
phpMyAdmin MEDIUM 6.8
CVE-2015-3902

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x be…

Patch available
Fix from $1,600 2015-05-26
phpMyAdmin MEDIUM 5.0
CVE-2014-9218EPSS 11%

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a den…

Patch available
Fix from $1,600 2014-12-08
phpMyAdmin MEDIUM 6.5
CVE-2013-5003

Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitr…

Mitigation only
Fix from $1,600 2013-07-31
phpMyAdmin MEDIUM 5.0
CVE-2013-4998

phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveal…

Mitigation only
Fix from $1,600 2013-07-31