Vulnerability index

Browse CVEs

156 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2013-4999 phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path i… phpMyAdmin Mitigation only Fix from $1,6002013-07-31 MEDIUM 5.0 CVE-2013-5000 phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path i… phpMyAdmin Mitigation only Fix from $1,6002013-07-31 MEDIUM 5.5 CVE-2013-4729 import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authen… phpMyAdmin Patch available Fix from $1,6002013-07-04 MEDIUM 6.5 CVE-2013-3240EPSS 5% Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated users to read arbitrary files … phpMyAdmin Mitigation only Fix from $1,6002013-04-26 MEDIUM 6.0 CVE-2013-3238EPSS 29% phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is no… phpMyAdmin Patch available Fix from $1,6002013-04-26 MEDIUM 6.1 CVE-2013-1937EPSS 6% Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inj… phpMyAdmin after 3.5.8 Fix from $1,6002013-04-16 HIGH 7.5 CVE-2012-5469EPSS 24% The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a… phpMyAdmin No fix yet Fix from $1,9502012-12-20 HIGH 7.5 CVE-2012-5159EPSS 75% phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modifica… phpMyAdmin Mitigation only Fix from $1,9502012-09-25 MEDIUM 5.0 CVE-2012-4219 show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals… phpMyAdmin Patch available Fix from $1,6002012-08-21 MEDIUM 5.0 CVE-2011-3646 phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to … phpMyAdmin Patch available Fix from $1,6002011-11-17 MEDIUM 6.8 CVE-2011-2643 Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to in… phpMyAdmin Patch available Fix from $1,6002011-08-01 MEDIUM 6.4 CVE-2011-2719 libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated wit… phpMyAdmin Patch available Fix from $1,6002011-08-01 MEDIUM 6.0 CVE-2011-2718 Multiple directory traversal vulnerabilities in the relational schema implementation in phpMyAdmin 3.4.x before 3.4.3.2 allow remote authenticated us… phpMyAdmin Patch available Fix from $1,6002011-08-01 MEDIUM 6.0 CVE-2011-2508 Directory traversal vulnerability in libraries/display_tbl.lib.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1, when a certain MIME tr… phpMyAdmin Patch available Fix from $1,6002011-07-14 HIGH 7.5 CVE-2011-2506EPSS 10% setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment clo… phpMyAdmin Patch available Fix from $1,9502011-07-14 MEDIUM 6.5 CVE-2011-2507 libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly q… phpMyAdmin Patch available Fix from $1,6002011-07-14 MEDIUM 6.4 CVE-2011-2505EPSS 13% libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns val… phpMyAdmin Patch available Fix from $1,6002011-07-14 MEDIUM 6.5 CVE-2011-0987 The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restri… phpMyAdmin Patch available Fix from $1,6002011-02-14 MEDIUM 5.0 CVE-2011-0986 phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly handle the absence of the (1) README, (2) ChangeLog, and (3) LICENSE … phpMyAdmin Patch available Fix from $1,6002011-02-14 MEDIUM 5.0 CVE-2010-4481 phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, … phpMyAdmin after 3.3.9.0 Fix from $1,6002010-12-17 HIGH 7.5 CVE-2010-3055EPSS 15% The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file,… phpMyAdmin Patch available Fix from $1,9502010-08-24 HIGH 10.0 CVE-2008-7251 libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack… phpMyAdmin Mitigation only Fix from $1,9502010-01-19 HIGH 10.0 CVE-2008-7252 libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vect… phpMyAdmin Patch available Fix from $1,9502010-01-19 MEDIUM 5.0 CVE-2009-4605 scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration an… phpMyAdmin Patch available Fix from $1,6002010-01-19 HIGH 7.5 CVE-2009-3697 SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attac… phpMyAdmin Patch available Fix from $1,9502009-10-16 HIGH 7.5 CVE-2009-1285EPSS 11% Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote at… phpMyAdmin Patch available Fix from $1,9502009-04-16 HIGH 7.5 CVE-2009-1149 CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject… phpMyAdmin after 3.1.3 Fix from $1,9502009-03-26 MEDIUM 5.0 CVE-2009-1148 Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to r… phpMyAdmin after 3.1.3 Fix from $1,6002009-03-26 MEDIUM 6.0 CVE-2008-5621 Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauth… phpMyAdmin Patch available Fix from $1,6002008-12-17 HIGH 8.5 CVE-2008-4096EPSS 11% libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to serve… phpMyAdmin after 2.11.9 Fix from $1,9502008-09-18