| phpMyAdmin | Number Of NVD | 270 | CRITICAL | 15 | HIGH | 53 | MEDIUM | 172 | LOW | 30 |
| URL | https://www.phpmyadmin.net/ | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Explanation | phpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL via the web. phpMyAdmin supports a wide range of operations on MySQL and MariaDB. Frequently used operations (managing databases, tables, columns, relations, indexes, users, permissions, etc.) can be performed via the user interface, with the ability to execute SQL statements directly. Translated and excerpted from [https://www.phpmyadmin.net/]. This is a convenient way to manage MySQL without having to type SQL directly. |
||||||||
| Tag | |||||||||
| No | Type | Name | URL |
|---|---|---|---|
| 1 | https://www.phpmyadmin.net/downloads/ | ||
| 2 | https://www.phpmyadmin.net/files/ | ||
| 3 | https://www.phpmyadmin.net/security/ |
| No | Name | Latest Version | Release date | Initial release | Normal Support | Security Support Service Pack Support |
Extended for a fee |
Critical | High | Medium | Low |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 61 | phpMyAdmin 5 | 5.2.3 | Oct. 8, 2025 | Dec. 26, 2019 | 2 | 5 | 4 | 0 | |||
| 62 | phpMyAdmin 4 | 4.9.7 | Oct. 15, 2020 | May 3, 2013 | 13 | 30 | 89 | 16 | |||
| 63 | phpMyAdmin 3 | 3.5.8.2 | July 28, 2013 | Sept. 27, 2008 | 4 | 8 | 48 | 10 | |||
| 64 | phpMyAdmin 2 | 2.11.11.3 | Feb. 11, 2011 | May 12, 1999 | 4 | 22 | 64 | 10 | |||
| 65 | phpMyAdmin 1 | 1.3.1 | Dec. 27, 1998 | Nov. 3, 1998 | 3 | 10 | 21 | 6 | |||
| 66 | phpMyAdmin 0 | 0.9.0 | 3 | 9 | 21 | 6 |
| No | CVSS3 CVSS2 |
Level Attach Vector |
Title | CWE | CVE | cpe23Uri | or higher | or less | more than | less than | Update date Published date |
Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 61 |
6.5 4.0 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin. An authenticated user can trigger a denial-of-service (DoS) attack by entering a very long password at the change password dialog. All 4.6.x versions (prior to … |
CWE-20
Improper Input Validation |
CVE-2016-6630 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 11:56 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 62 |
9.8 10.0 |
CRITICAL
Network |
An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by A… |
CWE-254
7PK - Security Features |
CVE-2016-6629 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 11:56 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 63 |
6.3 6.8 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicious SVG file. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.… |
CWE-254
7PK - Security Features |
CVE-2016-6628 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 11:56 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 64 |
5.3 5.0 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.… |
CWE-200
Information Exposure |
CVE-2016-6627 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 11:56 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 65 |
5.4 5.8 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin. An attacker could redirect a user to a malicious web page. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to… |
CWE-254
7PK - Security Features |
CVE-2016-6626 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 11:56 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 66 |
4.3 4.0 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin. An attacker can determine whether a user is logged in to phpMyAdmin. The user's session, username, and password are not compromised by this vulnerability. All 4… |
CWE-200
Information Exposure |
CVE-2016-6625 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 11:56 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 67 |
5.9 4.3 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin involving improper enforcement of the IP-based authentication rules. When phpMyAdmin is used with IPv6 in a proxy server environment, and the proxy server is in … |
CWE-254
7PK - Security Features |
CVE-2016-6624 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 11:56 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 68 |
6.5 4.0 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin. An authorized user can cause a denial-of-service (DoS) attack on a server by passing large values to a loop. All 4.6.x versions (prior to 4.6.4), 4.4.x versions… |
CWE-20
Improper Input Validation |
CVE-2016-6623 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 11:56 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 69 |
5.9 4.3 |
MEDIUM
Network |
An issue was discovered in phpMyAdmin. An unauthenticated user is able to execute a denial-of-service (DoS) attack by forcing persistent connections when phpMyAdmin is running with $cfg['AllowArbitra… |
CWE-399
Resource Management Errors |
CVE-2016-6622 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 11:56 2016-12-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 70 |
9.8 7.5 |
CRITICAL
Network |
An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution bec… |
CWE-502
Deserialization of Untrusted Data |
CVE-2016-6620 |
cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.3:* cpe:2.3:a:phpmyadmin:phpmyadmin:4.6.2:* cpe:2.3:a:phpmyadmin:phpmyadmin:4… |
2024-11-21 11:56 2016-12-11 |
Show | GitHub Exploit DB Packet Storm |