|
141
|
-
6.5
|
MEDIUM
|
Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pm…
|
CWE-89
SQL Injection
|
CVE-2013-5003
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4.1:* cpe:2.3:a:phpmyadmin:phpmyadmin…
|
|
|
|
|
2024-11-21 10:56
2013-07-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
142
|
-
3.5
|
LOW
|
Cross-site scripting (XSS) vulnerability in libraries/schema/Export_Relation_Schema.class.php in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject a…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5002
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4.1:* cpe:2.3:a:phpmyadmin:phpmyadmin…
|
|
|
|
|
2024-11-21 10:56
2013-07-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
143
|
-
3.5
|
LOW
|
Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to …
|
CWE-79
Cross-site Scripting
|
CVE-2013-5001
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4.1:* cpe:2.3:a:phpmyadmin:phpmyadmin…
|
|
|
|
|
2024-11-21 10:56
2013-07-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
144
|
-
5.0
|
MEDIUM
|
phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php …
|
CWE-200
Information Exposure
|
CVE-2013-5000
|
cpe:2.3:a:phpmyadmin:phpmyadmin:3.5.8:rc1 cpe:2.3:a:phpmyadmin:phpmyadmin:3.5.8:* cpe:2.3:a:phpmyadmin:phpmyadmin…
|
|
|
|
|
2024-11-21 10:56
2013-07-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
145
|
-
5.0
|
MEDIUM
|
phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to Error.class.php and…
|
CWE-200
Information Exposure
|
CVE-2013-4999
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4.1:* cpe:2.3:a:phpmyadmin:phpmyadmin…
|
|
|
|
|
2024-11-21 10:56
2013-07-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
146
|
-
5.0
|
MEDIUM
|
phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, relat…
|
CWE-200
Information Exposure
|
CVE-2013-4998
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4.1:* cpe:2.3:a:phpmyadmin:phpmyadmin…
|
|
|
|
|
2024-11-21 10:56
2013-07-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
147
|
-
4.3
|
MEDIUM
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving a JavaScript event in (1) an…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4997
|
cpe:2.3:a:phpmyadmin:phpmyadmin:3.5.8:rc1 cpe:2.3:a:phpmyadmin:phpmyadmin:3.5.8:* cpe:2.3:a:phpmyadmin:phpmyadmin…
|
|
|
|
|
2024-11-21 10:56
2013-07-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
148
|
-
4.3
|
MEDIUM
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1)…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4996
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4.1:* cpe:2.3:a:phpmyadmin:phpmyadmin…
|
|
|
|
|
2024-11-21 10:56
2013-07-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
149
|
-
3.5
|
LOW
|
Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query t…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4995
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4.1:* cpe:2.3:a:phpmyadmin:phpmyadmin…
|
|
|
|
|
2024-11-21 10:56
2013-07-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
150
|
-
5.5
|
MEDIUM
|
import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authenticated users to modify the GLOBALS superglobal ar…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4729
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.0.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 10:56
2013-07-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|