|
11
|
8.0
6.0
|
HIGH
Network
|
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search act…
|
CWE-89
SQL Injection
|
CVE-2020-10802
|
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*
|
5.0.0 4.0.0
|
|
|
5.0.2 4.9.5
|
2024-11-21 13:56
2020-03-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
12
|
8.0
6.0
|
HIGH
Network
|
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/Use…
|
CWE-89
SQL Injection
|
CVE-2020-10804
|
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*
|
5.0.0 4.0.0
|
|
|
5.0.2 4.9.5
|
2024-11-21 13:56
2020-03-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
13
|
8.8
6.5
|
HIGH
Network
|
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this …
|
CWE-89
SQL Injection
|
CVE-2020-5504
|
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*
|
5.0.0 4.0.0
|
|
|
5.0.1 4.9.4
|
2024-11-21 14:34
2020-01-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
14
|
9.8
7.5
|
CRITICAL
Network
|
phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.
|
NVD-CWE-noinfo
|
CVE-2019-19617
|
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*
|
|
|
|
4.9.2
|
2024-11-21 13:35
2019-12-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
15
|
9.8
7.5
|
CRITICAL
Network
|
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
|
CWE-89
SQL Injection
|
CVE-2019-18622
|
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*
|
|
|
|
4.9.2
|
2024-11-21 13:33
2019-11-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
16
|
6.5
5.8
|
MEDIUM
Network
|
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
|
CWE-352
Origin Validation Error
|
CVE-2019-12922
|
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*
|
|
4.9.0.1
|
|
|
2024-11-21 13:23
2019-09-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
17
|
6.5
4.3
|
MEDIUM
Network
|
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance…
|
CWE-352
Origin Validation Error
|
CVE-2019-12616
|
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*
|
|
|
|
4.9.0
|
2024-11-21 13:23
2019-06-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
18
|
9.8
7.5
|
CRITICAL
Network
|
An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.
|
CWE-89
SQL Injection
|
CVE-2019-11768
|
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*
|
|
|
|
4.9.0.1
|
2024-11-21 13:21
2019-06-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
19
|
5.9
4.3
|
MEDIUM
Network
|
An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the serv…
|
NVD-CWE-noinfo
|
CVE-2019-6799
|
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*
|
4.0.0
|
4.8.4
|
|
|
2024-11-21 13:47
2019-01-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
20
|
9.8
7.5
|
CRITICAL
Network
|
An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.
|
CWE-89
SQL Injection
|
CVE-2019-6798
|
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*
|
4.5.0
|
4.8.4
|
|
|
2024-11-21 13:47
2019-01-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|