Vulnerability index

Browse CVEs

156 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

phpMyAdmin MEDIUM 5.0
CVE-2013-4999

phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path i…

Mitigation only
Fix from $1,600 2013-07-31
phpMyAdmin MEDIUM 5.0
CVE-2013-5000

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path i…

Mitigation only
Fix from $1,600 2013-07-31
phpMyAdmin MEDIUM 5.5
CVE-2013-4729

import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authen…

Patch available
Fix from $1,600 2013-07-04
phpMyAdmin MEDIUM 6.5
CVE-2013-3240EPSS 5%

Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated users to read arbitrary files …

Mitigation only
Fix from $1,600 2013-04-26
phpMyAdmin MEDIUM 6.0
CVE-2013-3238EPSS 29%

phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is no…

Patch available
Fix from $1,600 2013-04-26
phpMyAdmin MEDIUM 6.1
CVE-2013-1937EPSS 6%

Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inj…

Fix: after 3.5.8
Fix from $1,600 2013-04-16
phpMyAdmin HIGH 7.5
CVE-2012-5469EPSS 24%

The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a…

No fix yet
Fix from $1,950 2012-12-20
phpMyAdmin HIGH 7.5
CVE-2012-5159EPSS 75%

phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modifica…

Mitigation only
Fix from $1,950 2012-09-25
phpMyAdmin MEDIUM 5.0
CVE-2012-4219

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals…

Patch available
Fix from $1,600 2012-08-21
phpMyAdmin MEDIUM 5.0
CVE-2011-3646

phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to …

Patch available
Fix from $1,600 2011-11-17
phpMyAdmin MEDIUM 6.8
CVE-2011-2643

Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to in…

Patch available
Fix from $1,600 2011-08-01
phpMyAdmin MEDIUM 6.4
CVE-2011-2719

libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated wit…

Patch available
Fix from $1,600 2011-08-01
phpMyAdmin MEDIUM 6.0
CVE-2011-2718

Multiple directory traversal vulnerabilities in the relational schema implementation in phpMyAdmin 3.4.x before 3.4.3.2 allow remote authenticated us…

Patch available
Fix from $1,600 2011-08-01
phpMyAdmin MEDIUM 6.0
CVE-2011-2508

Directory traversal vulnerability in libraries/display_tbl.lib.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1, when a certain MIME tr…

Patch available
Fix from $1,600 2011-07-14
phpMyAdmin HIGH 7.5
CVE-2011-2506EPSS 10%

setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment clo…

Patch available
Fix from $1,950 2011-07-14
phpMyAdmin MEDIUM 6.5
CVE-2011-2507

libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly q…

Patch available
Fix from $1,600 2011-07-14
phpMyAdmin MEDIUM 6.4
CVE-2011-2505EPSS 13%

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns val…

Patch available
Fix from $1,600 2011-07-14
phpMyAdmin MEDIUM 6.5
CVE-2011-0987

The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restri…

Patch available
Fix from $1,600 2011-02-14
phpMyAdmin MEDIUM 5.0
CVE-2011-0986

phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly handle the absence of the (1) README, (2) ChangeLog, and (3) LICENSE …

Patch available
Fix from $1,600 2011-02-14
phpMyAdmin MEDIUM 5.0
CVE-2010-4481

phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, …

Fix: after 3.3.9.0
Fix from $1,600 2010-12-17
phpMyAdmin HIGH 7.5
CVE-2010-3055EPSS 15%

The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file,…

Patch available
Fix from $1,950 2010-08-24
phpMyAdmin HIGH 10.0
CVE-2008-7251

libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack…

Mitigation only
Fix from $1,950 2010-01-19
phpMyAdmin HIGH 10.0
CVE-2008-7252

libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vect…

Patch available
Fix from $1,950 2010-01-19
phpMyAdmin MEDIUM 5.0
CVE-2009-4605

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration an…

Patch available
Fix from $1,600 2010-01-19
phpMyAdmin HIGH 7.5
CVE-2009-3697

SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attac…

Patch available
Fix from $1,950 2009-10-16
phpMyAdmin HIGH 7.5
CVE-2009-1285EPSS 11%

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote at…

Patch available
Fix from $1,950 2009-04-16
phpMyAdmin HIGH 7.5
CVE-2009-1149

CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject…

Fix: after 3.1.3
Fix from $1,950 2009-03-26
phpMyAdmin MEDIUM 5.0
CVE-2009-1148

Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to r…

Fix: after 3.1.3
Fix from $1,600 2009-03-26
phpMyAdmin MEDIUM 6.0
CVE-2008-5621

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauth…

Patch available
Fix from $1,600 2008-12-17
phpMyAdmin HIGH 8.5
CVE-2008-4096EPSS 11%

libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to serve…

Fix: after 2.11.9
Fix from $1,950 2008-09-18