|
51
|
5.3
5.0
|
MEDIUM
Network
|
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the…
|
CWE-200
Information Exposure
|
CVE-2016-9853
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 12:01
2016-12-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
52
|
5.3
5.0
|
MEDIUM
Network
|
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the…
|
CWE-200
Information Exposure
|
CVE-2016-9852
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 12:01
2016-12-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
53
|
5.3
5.0
|
MEDIUM
Network
|
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) …
|
CWE-254
7PK - Security Features
|
CVE-2016-9851
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 12:01
2016-12-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
54
|
5.3
5.0
|
MEDIUM
Network
|
An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x v…
|
CWE-254
7PK - Security Features
|
CVE-2016-9850
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 12:01
2016-12-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
55
|
9.8
7.5
|
CRITICAL
Network
|
An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x vers…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9849
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 12:01
2016-12-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
56
|
5.3
5.0
|
MEDIUM
Network
|
An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4…
|
CWE-200
Information Exposure
|
CVE-2016-9848
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 12:01
2016-12-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
57
|
5.3
5.0
|
MEDIUM
Network
|
An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpMyAdmin generates one at runtime. A vulnerability was reported where the way thi…
|
CWE-310
Cryptographic Issues
|
CVE-2016-9847
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.4:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 12:01
2016-12-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
58
|
8.1
6.8
|
HIGH
Network
|
An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remote code execution attack against certain PHP installations that are running with the dbase extension. All 4.6.x versions…
|
NVD-CWE-noinfo
|
CVE-2016-6633
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 11:56
2016-12-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
59
|
5.9
4.3
|
MEDIUM
Network
|
An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmin may not delete temporary files during the import of ESRI files. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (…
|
CWE-399
Resource Management Errors
|
CVE-2016-6632
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 11:56
2016-12-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
60
|
7.5
8.5
|
HIGH
Network
|
An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a use…
|
CWE-78
OS Command
|
CVE-2016-6631
|
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4…
|
|
|
|
|
2024-11-21 11:56
2016-12-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|