Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.0
CVE-2013-4999
phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path i…
phpMyAdmin
Mitigation only
MEDIUM 5.0
CVE-2013-5000
phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path i…
phpMyAdmin
Mitigation only
MEDIUM 5.5
CVE-2013-4729
import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authen…
phpMyAdmin
Patch available
MEDIUM 6.5
CVE-2013-3240EPSS 5%
Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated users to read arbitrary files …
phpMyAdmin
Mitigation only
MEDIUM 6.0
CVE-2013-3238EPSS 29%
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is no…
phpMyAdmin
Patch available
MEDIUM 6.1
CVE-2013-1937EPSS 6%
Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inj…
phpMyAdmin
after 3.5.8
HIGH 7.5
CVE-2012-5469EPSS 24%
The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a…
phpMyAdmin
No fix yet
HIGH 7.5
CVE-2012-5159EPSS 75%
phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modifica…
phpMyAdmin
Mitigation only
MEDIUM 5.0
CVE-2012-4219
show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals…
phpMyAdmin
Patch available
MEDIUM 5.0
CVE-2011-3646
phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to …
phpMyAdmin
Patch available
MEDIUM 6.8
CVE-2011-2643
Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to in…
phpMyAdmin
Patch available
MEDIUM 6.4
CVE-2011-2719
libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated wit…
phpMyAdmin
Patch available
MEDIUM 6.0
CVE-2011-2718
Multiple directory traversal vulnerabilities in the relational schema implementation in phpMyAdmin 3.4.x before 3.4.3.2 allow remote authenticated us…
phpMyAdmin
Patch available
MEDIUM 6.0
CVE-2011-2508
Directory traversal vulnerability in libraries/display_tbl.lib.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1, when a certain MIME tr…
phpMyAdmin
Patch available
HIGH 7.5
CVE-2011-2506EPSS 10%
setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment clo…
phpMyAdmin
Patch available
MEDIUM 6.5
CVE-2011-2507
libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly q…
phpMyAdmin
Patch available
MEDIUM 6.4
CVE-2011-2505EPSS 13%
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns val…
phpMyAdmin
Patch available
MEDIUM 6.5
CVE-2011-0987
The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restri…
phpMyAdmin
Patch available
MEDIUM 5.0
CVE-2011-0986
phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly handle the absence of the (1) README, (2) ChangeLog, and (3) LICENSE …
phpMyAdmin
Patch available
MEDIUM 5.0
CVE-2010-4481
phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, …
phpMyAdmin
after 3.3.9.0
HIGH 7.5
CVE-2010-3055EPSS 15%
The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file,…
phpMyAdmin
Patch available
HIGH 10.0
CVE-2008-7251
libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack…
phpMyAdmin
Mitigation only
HIGH 10.0
CVE-2008-7252
libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vect…
phpMyAdmin
Patch available
MEDIUM 5.0
CVE-2009-4605
scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration an…
phpMyAdmin
Patch available
HIGH 7.5
CVE-2009-3697
SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attac…
phpMyAdmin
Patch available
HIGH 7.5
CVE-2009-1285EPSS 11%
Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote at…
phpMyAdmin
Patch available
HIGH 7.5
CVE-2009-1149
CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject…
phpMyAdmin
after 3.1.3
MEDIUM 5.0
CVE-2009-1148
Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to r…
phpMyAdmin
after 3.1.3
MEDIUM 6.0
CVE-2008-5621
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauth…
phpMyAdmin
Patch available
HIGH 8.5
CVE-2008-4096EPSS 11%
libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to serve…
phpMyAdmin
after 2.11.9