Vulnerability index

Browse CVEs

24 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

phpMyAdmin MEDIUM 6.1
CVE-2020-11441

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on a…

No fix yet
Fix from $1,600 2020-03-31
phpMyAdmin HIGH 8.8
CVE-2018-10188

phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations…

No fix yet
Fix from $1,950 2018-04-19
phpMyAdmin HIGH 7.5
CVE-2017-1000016

A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA…

Mitigation only
Fix from $1,950 2017-07-17
phpMyAdmin MEDIUM 6.1
CVE-2017-1000015

phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters

Mitigation only
Fix from $1,600 2017-07-17
phpMyAdmin MEDIUM 6.5
CVE-2013-5003

Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitr…

Mitigation only
Fix from $1,600 2013-07-31
phpMyAdmin MEDIUM 5.0
CVE-2013-4998

phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveal…

Mitigation only
Fix from $1,600 2013-07-31
phpMyAdmin MEDIUM 5.0
CVE-2013-4999

phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path i…

Mitigation only
Fix from $1,600 2013-07-31
phpMyAdmin MEDIUM 5.0
CVE-2013-5000

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path i…

Mitigation only
Fix from $1,600 2013-07-31
phpMyAdmin MEDIUM 6.5
CVE-2013-3240EPSS 5%

Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated users to read arbitrary files …

Mitigation only
Fix from $1,600 2013-04-26
phpMyAdmin HIGH 7.5
CVE-2012-5469EPSS 24%

The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a…

No fix yet
Fix from $1,950 2012-12-20
phpMyAdmin HIGH 7.5
CVE-2012-5159EPSS 75%

phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modifica…

Mitigation only
Fix from $1,950 2012-09-25
phpMyAdmin HIGH 10.0
CVE-2008-7251

libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack…

Mitigation only
Fix from $1,950 2010-01-19
phpMyAdmin MEDIUM 6.8
CVE-2007-2245

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (…

Mitigation only
Fix from $1,600 2007-04-25
phpMyAdmin MEDIUM 5.0
CVE-2007-0095

phpMyAdmin 2.9.1.1 allows remote attackers to obtain sensitive information via a direct request for themes/darkblue_orange/layout.inc.php, which reve…

No fix yet
Fix from $1,600 2007-01-05
phpMyAdmin HIGH 7.5
CVE-2006-6374

Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response spl…

Mitigation only
Fix from $1,950 2006-12-07
phpMyAdmin MEDIUM 5.0
CVE-2006-6373

PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the pat…

Mitigation only
Fix from $1,600 2006-12-07
phpMyAdmin HIGH 7.5
CVE-2006-1804

SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.

No fix yet
Fix from $1,950 2006-04-18
phpMyAdmin HIGH 7.5
CVE-2005-4450

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a…

Mitigation only
Fix from $1,950 2005-12-21
phpMyAdmin MEDIUM 6.3
CVE-2005-4349

SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the …

No fix yet
Fix from $1,600 2005-12-19
phpMyAdmin MEDIUM 5.0
CVE-2005-4079

The register_globals emulation in phpMyAdmin 2.7.0 rc1 allows remote attackers to exploit other vulnerabilities in phpMyAdmin by modifying the import…

Mitigation only
Fix from $1,600 2005-12-08
phpMyAdmin MEDIUM 5.0
CVE-2005-3622

phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libra…

Mitigation only
Fix from $1,600 2005-11-16
phpMyAdmin MEDIUM 5.0
CVE-2005-0459

phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to selec…

No fix yet
Fix from $1,600 2005-05-02
phpMyAdmin HIGH 10.0
CVE-2004-1147EPSS 12%

phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands v…

Mitigation only
Fix from $1,950 2005-01-10
phpMyAdmin MEDIUM 5.0
CVE-2004-1148

phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile paramete…

Mitigation only
Fix from $1,600 2005-01-10