Vulnerability index

Browse CVEs

156 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

phpMyAdmin MEDIUM 6.4
CVE-2008-3456

phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for re…

Fix: after 2.11.7.0
Fix from $1,600 2008-08-04
phpMyAdmin MEDIUM 5.1
CVE-2008-1149

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to overr…

Fix: after 2.11.4
Fix from $1,600 2008-03-04
phpMyAdmin MEDIUM 6.5
CVE-2007-5976

SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execu…

Fix: after 2.11.2
Fix from $1,600 2007-11-15
phpMyAdmin MEDIUM 6.8
CVE-2007-2245

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (…

Mitigation only
Fix from $1,600 2007-04-25
phpMyAdmin HIGH 7.1
CVE-2007-1325

The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, w…

Fix: after 2.10.0.1
Fix from $1,950 2007-03-07
phpMyAdmin HIGH 7.5
CVE-2006-6944

phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false headers.

Fix: after 2.9.1
Fix from $1,950 2007-01-19
phpMyAdmin MEDIUM 5.0
CVE-2006-6943

PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/dar…

Fix: after 2.9.1
Fix from $1,600 2007-01-19
phpMyAdmin MEDIUM 6.8
CVE-2007-0341

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inje…

Patch available
Fix from $1,600 2007-01-18
phpMyAdmin HIGH 10.0
CVE-2007-0203

Multiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have unknown impact and attack vectors.

Fix: after 2.9.1.1
Fix from $1,950 2007-01-11
phpMyAdmin MEDIUM 6.8
CVE-2007-0204

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.9.2-rc1 allow remote attackers to inject arbitrary web script or HTML via …

Fix: after 2.9.1.1
Fix from $1,600 2007-01-11
phpMyAdmin MEDIUM 5.0
CVE-2007-0095

phpMyAdmin 2.9.1.1 allows remote attackers to obtain sensitive information via a direct request for themes/darkblue_orange/layout.inc.php, which reve…

No fix yet
Fix from $1,600 2007-01-05
phpMyAdmin HIGH 7.5
CVE-2006-6374

Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response spl…

Mitigation only
Fix from $1,950 2006-12-07
phpMyAdmin MEDIUM 5.0
CVE-2006-6373

PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the pat…

Mitigation only
Fix from $1,600 2006-12-07
phpMyAdmin MEDIUM 5.1
CVE-2006-5116

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdmin before 2.9.1-rc1 allow remote attackers to perform unauthorized actions as a…

Patch available
Fix from $1,600 2006-10-03
phpMyAdmin MEDIUM 5.0
CVE-2006-5117

phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to …

Patch available
Fix from $1,600 2006-10-03
phpMyAdmin MEDIUM 5.8
CVE-2006-3388

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via the table para…

Patch available
Fix from $1,600 2006-07-06
phpMyAdmin MEDIUM 6.8
CVE-2006-2418

Cross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary web script or …

Patch available
Fix from $1,600 2006-05-16
phpMyAdmin HIGH 7.5
CVE-2006-1804

SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.

No fix yet
Fix from $1,950 2006-04-18
phpMyAdmin HIGH 7.5
CVE-2005-4450

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a…

Mitigation only
Fix from $1,950 2005-12-21
phpMyAdmin MEDIUM 6.3
CVE-2005-4349

SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the …

No fix yet
Fix from $1,600 2005-12-19
phpMyAdmin MEDIUM 5.0
CVE-2005-4079

The register_globals emulation in phpMyAdmin 2.7.0 rc1 allows remote attackers to exploit other vulnerabilities in phpMyAdmin by modifying the import…

Mitigation only
Fix from $1,600 2005-12-08
phpMyAdmin MEDIUM 5.0
CVE-2005-3621

CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attackers to conduct HTTP response splitting attacks via unspecified script…

Patch available
Fix from $1,600 2005-11-16
phpMyAdmin MEDIUM 5.0
CVE-2005-3622

phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libra…

Mitigation only
Fix from $1,600 2005-11-16
phpMyAdmin MEDIUM 5.0
CVE-2005-3299EPSS 16%

PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__…

Patch available
Fix from $1,600 2005-10-23
phpMyAdmin MEDIUM 5.0
CVE-2005-3300

The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array…

Patch available
Fix from $1,600 2005-10-23
phpMyAdmin HIGH 7.5
CVE-2005-0567

Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) them…

Patch available
Fix from $1,950 2005-05-02
phpMyAdmin MEDIUM 5.0
CVE-2005-0459

phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to selec…

No fix yet
Fix from $1,600 2005-05-02
phpMyAdmin MEDIUM 5.0
CVE-2005-0544

phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php…

Patch available
Fix from $1,600 2005-05-02
phpMyAdmin HIGH 10.0
CVE-2004-1147EPSS 12%

phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands v…

Mitigation only
Fix from $1,950 2005-01-10
phpMyAdmin MEDIUM 5.0
CVE-2004-1148

phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile paramete…

Mitigation only
Fix from $1,600 2005-01-10