|
261
|
-
6.8
|
MEDIUM
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zer…
|
NVD-CWE-Other
|
CVE-2004-1055
|
cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.0_pl2:* cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.0_pl1:* cpe:2.3:a:phpmyadmin:phpm…
|
|
|
|
|
2017-07-11 10:30
2005-03-1
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
262
|
-
4.3
|
MEDIUM
|
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in s…
|
CWE-79
Cross-site Scripting
|
CVE-2005-0543
|
cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.1_rc1:* cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.1:* cpe:2.3:a:phpmyadmin:phpmyadm…
|
|
|
|
|
2017-07-11 10:32
2005-02-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
263
|
-
10.0
|
HIGH
|
phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.
|
NVD-CWE-Other
|
CVE-2004-1147
|
cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.0_pl3:* cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.0_pl2:* cpe:2.3:a:phpmyadmin:phpm…
|
|
|
|
|
2017-07-11 10:30
2005-01-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264
|
-
5.0
|
MEDIUM
|
phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.
|
NVD-CWE-Other
|
CVE-2004-1148
|
cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.0_pl3:* cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.0_pl2:* cpe:2.3:a:phpmyadmin:phpm…
|
|
|
|
|
2017-07-11 10:30
2005-01-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265
|
-
7.5
|
HIGH
|
The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in uns…
|
NVD-CWE-Other
|
CVE-2004-2630
|
cpe:2.3:a:phpmyadmin:phpmyadmin:2.6.0_pl1:* cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.7_pl1:* cpe:2.3:a:phpmyadmin:phpm…
|
|
|
|
|
2017-07-20 10:29
2004-12-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266
|
-
7.5
|
HIGH
|
Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.
|
NVD-CWE-Other
|
CVE-2004-2631
|
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.7:* cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.6_rc2:* cpe:2.3:a:phpmyadmin:phpmyadm…
|
|
|
|
|
2017-07-20 10:29
2004-12-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267
|
-
7.5
|
HIGH
|
phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables.
|
NVD-CWE-Other
|
CVE-2004-2632
|
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.7:* cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.6_rc2:* cpe:2.3:a:phpmyadmin:phpmyadm…
|
|
|
|
|
2017-07-20 10:29
2004-12-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268
|
-
5.0
|
MEDIUM
|
Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.
|
NVD-CWE-Other
|
CVE-2004-0129
|
cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5_rc2:* cpe:2.3:a:phpmyadmin:phpmyadmin:2.5.5_rc1:* cpe:2.3:a:phpmyadmin:phpm…
|
|
|
|
|
2017-10-10 10:30
2004-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269
|
-
7.5
|
HIGH
|
phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in t…
|
NVD-CWE-Other
|
CVE-2001-1060
|
cpe:2.3:a:phpmyadmin:phpmyadmin:2.2_rc3:* cpe:2.3:a:phpmyadmin:phpmyadmin:2.2_rc2:* cpe:2.3:a:phpmyadmin:phpmyadm…
|
|
|
|
|
2009-04-3 13:00
2001-07-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270
|
-
7.5
|
HIGH
|
Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.
|
NVD-CWE-Other
|
CVE-2001-0478
|
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*
|
|
2.2.0
|
|
|
2008-09-6 05:24
2001-06-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|