| phpMyAdmin | Number Of NVD | 270 | CRITICAL | 15 | HIGH | 53 | MEDIUM | 172 | LOW | 30 |
| URL | https://www.phpmyadmin.net/ | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Explanation | phpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL via the web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB. Frequently used operations (managing databases, tables, columns, relations, indexes, users, permissions, etc.) can be performed via the user interface, with the ability to execute SQL statements directly. Translated and excerpted from [https://www.phpmyadmin.net/]. This is a convenient way to manage MySQL without having to type SQL directly. |
||||||||
| Tag | |||||||||
| No | Type | Name | URL |
|---|---|---|---|
| 1 | https://www.phpmyadmin.net/downloads/ | ||
| 2 | https://www.phpmyadmin.net/files/ | ||
| 3 | https://www.phpmyadmin.net/security/ |
| No | Name | Latest Version | Release date | Initial release | Normal Support | Security Support Service Pack Support |
Extended for a fee |
Critical | High | Medium | Low |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 41 | phpMyAdmin 5 | 5.2.3 | Oct. 8, 2025 | Dec. 26, 2019 | 2 | 5 | 4 | 0 | |||
| 42 | phpMyAdmin 4 | 4.9.7 | Oct. 15, 2020 | May 3, 2013 | 13 | 30 | 89 | 16 | |||
| 43 | phpMyAdmin 3 | 3.5.8.2 | July 28, 2013 | Sept. 27, 2008 | 4 | 8 | 48 | 10 | |||
| 44 | phpMyAdmin 2 | 2.11.11.3 | Feb. 11, 2011 | May 12, 1999 | 4 | 22 | 64 | 10 | |||
| 45 | phpMyAdmin 1 | 1.3.1 | Dec. 27, 1998 | Nov. 3, 1998 | 3 | 10 | 21 | 6 | |||
| 46 | phpMyAdmin 0 | 0.9.0 | 3 | 9 | 21 | 6 |
| No | CVSS3 CVSS2 |
Level Attach Vector |
Title | CWE | CVE | cpe23Uri | or higher | or less | more than | less than | Update date Published date |
Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 41 |
7.5 5.0 |
HIGH
Network |
An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) attack. All 4.6.x versions (prior to 4.6.5) are aff… |
CWE-20
Improper Input Validation |
CVE-2016-9863 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 12:01 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 42 |
7.5 5.0 |
HIGH
Network |
An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected. |
CWE-94
Code Injection |
CVE-2016-9862 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 12:01 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 43 |
7.5 5.0 |
HIGH
Network |
An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.… |
CWE-254
7PK - Security Features |
CVE-2016-9861 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 12:01 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 44 |
5.9 4.3 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbitraryServer']=true. All 4.6.x versions (prior to 4… |
CWE-20
Improper Input Validation |
CVE-2016-9860 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 12:01 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 45 |
5.3 5.0 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versi… |
CWE-20
Improper Input Validation |
CVE-2016-9859 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 12:01 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 46 |
5.3 5.0 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in saved searches feature. All 4.6.x versions (prior to 4.6.5), 4.4… |
CWE-20
Improper Input Validation |
CVE-2016-9858 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 12:01 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 47 |
6.1 4.3 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin. XSS is possible because of a weakness in a regular expression used in some JavaScript processing. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to … |
CWE-79
Cross-site Scripting |
CVE-2016-9857 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 12:01 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 48 |
6.1 4.3 |
MEDIUM
Network |
An XSS issue was discovered in phpMyAdmin because of an improper fix for CVE-2016-2559 in PMASA-2016-10. This issue is resolved by using a copy of a hash to avoid a race condition. All 4.6.x versions… |
CWE-79
Cross-site Scripting |
CVE-2016-9856 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 12:01 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 49 |
5.3 5.0 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the… |
CWE-200
Information Exposure |
CVE-2016-9855 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 12:01 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 50 |
5.3 5.0 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the… |
CWE-200
Information Exposure |
CVE-2016-9854 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 12:01 2016-12-11 |
Show | GitHub Exploit DB Packet Storm |