Show filters
273 Total Results
Displaying 1-10 of 273
Sort by:
Attacker Value
Very High
CVE-2005-3299
Disclosure Date: October 23, 2005 (last updated February 22, 2025)
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.
3
Attacker Value
Unknown
CVE-2009-1151
Disclosure Date: March 26, 2009 (last updated July 17, 2024)
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.
1
Attacker Value
Unknown
CVE-2023-25727
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
0
Attacker Value
Unknown
CVE-2020-22452
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
0
Attacker Value
Unknown
CVE-2022-2407
Disclosure Date: August 22, 2022 (last updated October 08, 2023)
The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-0813
Disclosure Date: March 08, 2022 (last updated October 07, 2023)
PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.
0
Attacker Value
Unknown
CVE-2022-23808
Disclosure Date: January 22, 2022 (last updated October 07, 2023)
An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.
0
Attacker Value
Unknown
CVE-2022-23807
Disclosure Date: January 22, 2022 (last updated October 07, 2023)
An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.
0
Attacker Value
Unknown
CVE-2020-22278
Disclosure Date: November 04, 2020 (last updated February 22, 2025)
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
0
Attacker Value
Unknown
CVE-2020-26935
Disclosure Date: October 10, 2020 (last updated February 22, 2025)
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.
0