|
131
|
-
3.5
|
LOW
|
Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5274
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.7:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.6:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 11:11
2014-08-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
132
|
-
3.5
|
LOW
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5273
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.7:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.6:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 11:11
2014-08-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
133
|
-
4.0
|
MEDIUM
|
server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4987
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.5:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 11:11
2014-07-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
134
|
-
3.5
|
LOW
|
Multiple cross-site scripting (XSS) vulnerabilities in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allow remote authenticated users to inject ar…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4986
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.5:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 11:11
2014-07-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
135
|
-
3.5
|
LOW
|
Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 all…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4955
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.5:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 11:11
2014-07-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
136
|
-
3.5
|
LOW
|
Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLinks function in libraries/structure.lib.php in phpMyAdmin 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrar…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4954
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.5:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 11:11
2014-07-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
137
|
-
3.5
|
LOW
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted ta…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4349
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 11:10
2014-06-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
138
|
-
3.5
|
LOW
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) tab…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4348
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.2.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 11:10
2014-06-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
139
|
-
3.5
|
LOW
|
Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin before 4.1.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename in an import action.
|
CWE-79
Cross-site Scripting
|
CVE-2014-1879
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.1.5:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.1.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
4.1.6
|
|
|
2024-11-21 11:05
2014-02-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
140
|
-
4.3
|
MEDIUM
|
phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.
|
CWE-20
Improper Input Validation
|
CVE-2013-5029
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4.2:* cpe:2.3:a:phpmyadmin:phpmyadmin…
|
|
|
|
|
2024-11-21 10:56
2013-08-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|