|
181
|
-
7.5
|
HIGH
|
setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to …
|
CWE-94
Code Injection
|
CVE-2011-2506
|
cpe:2.3:a:phpmyadmin:phpmyadmin:3.4.3.0:* cpe:2.3:a:phpmyadmin:phpmyadmin:3.4.2.0:* cpe:2.3:a:phpmyadmin:phpmyadm…
|
|
|
|
|
2024-11-21 10:28
2011-07-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
182
|
-
6.4
|
MEDIUM
|
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the quer…
|
CWE-94
Code Injection
|
CVE-2011-2505
|
cpe:2.3:a:phpmyadmin:phpmyadmin:3.4.3.0:* cpe:2.3:a:phpmyadmin:phpmyadmin:3.4.2.0:* cpe:2.3:a:phpmyadmin:phpmyadm…
|
|
|
|
|
2024-11-21 10:28
2011-07-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
183
|
-
6.5
|
MEDIUM
|
The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for rem…
|
CWE-20
Improper Input Validation
|
CVE-2011-0987
|
cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.9.1:* cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.9.0:* cpe:2.3:a:phpmyadmin:phpmyadm…
|
|
|
|
|
2024-11-21 10:25
2011-02-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
184
|
-
5.0
|
MEDIUM
|
phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly handle the absence of the (1) README, (2) ChangeLog, and (3) LICENSE files, which allows remote attackers to obtain the…
|
CWE-20
Improper Input Validation
|
CVE-2011-0986
|
cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.9.0:* cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.8:* cpe:2.3:a:phpmyadmin:phpmyadmin…
|
|
|
|
|
2024-11-21 10:25
2011-02-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
185
|
-
5.0
|
MEDIUM
|
phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function.
|
CWE-287
Improper Authentication
|
CVE-2010-4481
|
cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.8:* cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.8.1:* cpe:2.3:a:phpmyadmin:phpmyadmin…
|
|
3.3.9.0
|
|
|
2024-11-21 10:21
2010-12-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
186
|
-
4.3
|
MEDIUM
|
error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as de…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4480
|
cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.9.0:* cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.8.1:*
|
|
|
|
|
2024-11-21 10:21
2010-12-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
187
|
-
4.3
|
MEDIUM
|
Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in libraries/common.lib.php in the database (db) search script in phpMyAdmin 2.11.x before 2.11.11.1 and 3.x before 3.3.8.1 a…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4329
|
cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.8:* cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.7:* cpe:2.3:a:phpmyadmin:phpmyadmin:3…
|
|
|
|
|
2024-11-21 10:20
2010-12-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
188
|
-
4.3
|
MEDIUM
|
Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server n…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3263
|
cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.6.0:* cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.5.1:* cpe:2.3:a:phpmyadmin:phpmyadm…
|
|
|
|
|
2024-11-21 10:18
2010-09-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
189
|
-
4.3
|
MEDIUM
|
Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to a PHP backtr…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2958
|
cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.5.1:* cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.5.0:* cpe:2.3:a:phpmyadmin:phpmyadm…
|
|
|
|
|
2024-11-21 10:17
2010-09-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190
|
-
4.3
|
MEDIUM
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3056
|
cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.5.0:* cpe:2.3:a:phpmyadmin:phpmyadmin:3.3.4.0:* cpe:2.3:a:phpmyadmin:phpmyadm…
|
|
|
|
|
2024-11-21 10:17
2010-08-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|