Vulnerability index

Browse CVEs

156 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2016-6614 An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username su… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.3 CVE-2016-6613 An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is … phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 6.5 CVE-2016-6612 An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. A… phpMyAdmin Patch available Fix from $1,6002016-12-11 HIGH 8.1 CVE-2016-6611 An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the expo… phpMyAdmin Patch available Fix from $1,9502016-12-11 HIGH 8.8 CVE-2016-6609 An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature… phpMyAdmin Patch available Fix from $1,9502016-12-11 MEDIUM 6.1 CVE-2016-6608 XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted da… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 6.1 CVE-2016-6607 XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS edito… phpMyAdmin Patch available Fix from $1,6002016-12-11 HIGH 8.1 CVE-2016-6606 An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This ca… phpMyAdmin Patch available Fix from $1,9502016-12-11 MEDIUM 6.1 CVE-2016-5099 Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web s… phpMyAdmin Patch available Fix from $1,6002016-07-05 MEDIUM 5.3 CVE-2016-5098 Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the ex… phpMyAdmin Patch available Fix from $1,6002016-07-05 CRITICAL 9.8 CVE-2016-5734EPSS 81% phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_repla… phpMyAdmin Patch available Fix from $2,3002016-07-03 MEDIUM 6.1 CVE-2016-5733 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allow remote … phpMyAdmin Patch available Fix from $1,6002016-07-03 MEDIUM 6.1 CVE-2016-5732 Multiple cross-site scripting (XSS) vulnerabilities in the partition-range implementation in templates/table/structure/display_partitions.phtml in th… phpMyAdmin Patch available Fix from $1,6002016-07-03 MEDIUM 6.1 CVE-2016-5731 Cross-site scripting (XSS) vulnerability in examples/openid.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 a… phpMyAdmin Patch available Fix from $1,6002016-07-03 MEDIUM 5.3 CVE-2016-5730 phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to obtain sensitive information via vectors … phpMyAdmin Patch available Fix from $1,6002016-07-03 HIGH 7.5 CVE-2016-5706 js/get_scripts.js.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to cause a denial o… phpMyAdmin Patch available Fix from $1,9502016-07-03 MEDIUM 6.1 CVE-2016-5704 Cross-site scripting (XSS) vulnerability in the table-structure page in phpMyAdmin 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web… phpMyAdmin Patch available Fix from $1,6002016-07-03 MEDIUM 6.1 CVE-2016-5701 setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to condu… phpMyAdmin Patch available Fix from $1,6002016-07-03 MEDIUM 6.8 CVE-2016-2562 The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL se… phpMyAdmin Patch available Fix from $1,6002016-03-01 MEDIUM 5.4 CVE-2016-2561 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to … phpMyAdmin Patch available Fix from $1,6002016-03-01 MEDIUM 6.1 CVE-2016-2560 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remot… phpMyAdmin Patch available Fix from $1,6002016-03-01 MEDIUM 5.4 CVE-2016-2559 Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL parser in phpMyAdmin 4.5.x bef… phpMyAdmin Patch available Fix from $1,6002016-03-01 HIGH 7.5 CVE-2016-1927 The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Mat… phpMyAdmin Patch available Fix from $1,9502016-02-20 MEDIUM 5.3 CVE-2015-8669 libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to ob… phpMyAdmin Patch available Fix from $1,6002015-12-26 MEDIUM 5.0 CVE-2015-7873 The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url pa… phpMyAdmin Patch available Fix from $1,6002015-10-28 MEDIUM 5.0 CVE-2015-6830EPSS 10% libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass… phpMyAdmin Patch available Fix from $1,6002015-09-14 MEDIUM 6.8 CVE-2015-3902 Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x be… phpMyAdmin Patch available Fix from $1,6002015-05-26 MEDIUM 5.0 CVE-2014-9218EPSS 11% libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a den… phpMyAdmin Patch available Fix from $1,6002014-12-08 MEDIUM 6.5 CVE-2013-5003 Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitr… phpMyAdmin Mitigation only Fix from $1,6002013-07-31 MEDIUM 5.0 CVE-2013-4998 phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveal… phpMyAdmin Mitigation only Fix from $1,6002013-07-31